BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Next.js Critical Flaw in ImageResponse Allows Server RCE

Critical Next.js RCE flaw patched; update to 16.3.6 immediately.

  • A critical vulnerability (CVE-2026-94545, CVSS 9.5) in Next.js versions 16.2.0 through 16.3.5 allows remote code execution via the ImageResponse feature when running on the Node.js runtime.
  • Vercel released a fix in version 16.3.6 on September 22; the flaw stems from the underlying Satori library that fails to escape attacker‑controlled values in SVG output.
  • Affected applications are those that pass user‑controlled data into SVG content during Open Graph image generation; the Edge runtime is not affected, and no public exploits have been reported as of September 23.

Swati Khandelwal reported on September 23, 2026, that a critical server‑side code execution vulnerability in Next.js affects versions 16.2.0 through 16.3.5 when the ImageResponse feature runs on the Node.js runtime. The flaw, tracked as CVE-2026-94545 with a CVSS score of 9.5, allows attackers to execute arbitrary code by injecting crafted values into the SVG content generated for social preview images, according to Vercel‘s advisory.

- Advertisement -

Vercel, which develops Next.js, fixed the issue on September 22 in version 16.3.6, and the vulnerability does not affect Next.js 15 or the Edge runtime of ImageResponse. The root cause lies in Satori, Vercel‘s library that converts image layouts into SVG code before generating the final PNG; Satori‘s own advisory confirms that certain values reach SVG output without being properly escaped, potentially leading to code execution when combined with other dependencies.

Vercel provided details and a workaround: keep attacker‑controlled values out of SVG content, attributes, and styles rendered by the Node.js ImageResponse. The only patched version is 16.3.6, and developers using Satori directly should update to version 0.33.5. As of September 23, no public exploit code or attacks have been confirmed, and Vercel did not state whether hosted apps are automatically protected or provide a way to detect previous abuse.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Lightning Gets First Quantum-Proof Defense

East Texas A&M University researchers developed PQLN, the first quantum-proof defense for Bitcoin’s Lightning...

Calacanis bets four self-driving stocks will be bought in 24 months

Early Uber investor Jason Calacanis bought small positions in WeRide, PONY, LCID, and RIVN,...

Bessent frontrunner for Trump AI czar role

US Treasury Secretary Scott Bessent is reportedly the frontrunner to become President Trump’s next...

Salesforce ties Anthropic bet, Slack AI to counter SaaS threat

Salesforce CEO Marc Benioff stated Microsoft’s OpenAI ties blocked Salesforce from investing, leading to...

UN Security Council to Hear AI CEOs on Risks Before Trump-Xi Meet

Anthropic, OpenAI, DeepSeek, and Moonshot will brief the UN Security Council on AI risks...

Must Read

How to Buy VPN With Bitcoin Using CyberGhost VPN

In this step-by-step guide, you will learn how to purchase a VPN (Virtual Private Network) subscription using Bitcoin, a popular cryptocurrency, and CyberGhost VPN,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading