CVE Tools

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

The Hacker NewsBy The Hacker News

PatchNext.js

Our summary

Vercel has patched CVE-2026-94545, a critical Next.js vulnerability that can allow server-side code execution when Node.js ImageResponse processes attacker-controlled values in generated SVG content. The issue affects Next.js 16.2.0 through 16.3.5; Next.js 15 and the Edge implementation of ImageResponse are not affected. Organizations should upgrade to Next.js 16.3.6, while developers using Satori directly should update to version 0.33.5.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store