Security Bulletin

Next.js CVE-2026-94545: Critical ImageResponse Vulnerability Enables RCE via SVG

3 min read Updated

A critical remote code execution vulnerability was disclosed in Next.js on September 22, 2026, and an out-of-band security update was released to fix it. 

CVE-2026-94545 is a remote code execution vulnerability in next/og, the feature Next.js applications use to generate images on demand. The GitHub advisory rates it 9.5 on CVSS v4.0. An unauthenticated attacker can reach it over the network, and the root cause is an upstream SVG-escaping vulnerability that applications inherit without realizing it. 

What Is CVE-2026-94545? Breaking Down the next/og ImageResponse Flaw 

CVE-2026-94545 affects the Node.js ImageResponse implementation in next/og, the feature Next.js applications use to generate Open Graph images, social preview cards, and other server-rendered graphics on demand. When an application passes attacker-controlled data into SVG content, attributes, or CSS styles during image generation, that data reaches a vulnerable rendering path. Successful exploitation can lead to remote code execution on the server handling the request. 

The actual impact depends on how the application is hosted and what the image-generation process can reach. A compromised environment could expose server-side data, cloud credentials, or internal services, allow modification of hosted content, disrupt operations, or give attackers a foothold for further attacks. 

Root Cause: Improper SVG Escaping in Upstream Satori 

The vulnerability arises from an upstream Satori SVG-escaping vulnerability that affects Next.js’s Node.js ImageResponse implementation. Satori is the library next/og depends on to turn markup into SVG for image generation. Satori failed to properly escape certain values before including them in generated SVG output, allowing crafted values to be interpreted as SVG markup. 

The crafted SVG can then reach a downstream rendering pipeline that processes attacker-defined markup. The advisory ties the escalation to code execution to the downstream SVG parser that handles that document. 

Next.js patched its compiled @vercel/og artifacts to harden serialization and shipped an @vercel/og@1.0.1 patch alongside the framework release. 

Which Next.js Applications Are Affected 

Three conditions decide whether a Next.js deployment is exposed: 

  • The application must use the Node.js runtime implementation of ImageResponse. Applications on the Edge runtime are not affected. 
  • The application must place attacker-controlled values into SVG content, attributes, or styles during image generation. Applications that only render trusted content through ImageResponse are not affected. 
  • The application must run an affected version, Next.js 16.2.0 up to 16.3.5. 

The CVE affects Next.js 16.2.0 through 16.3.5 in applications that use the Node.js ImageResponse implementation. Next.js 15.5.26 was also released as part of the security update. The typical exposure is an Open Graph image route that reads a query-string parameter and renders it inside SVG markup.  For example, an application might drop a request value straight into an SVG title element. 

Affected and Fixed Versions 

Detail  Value 
Affected Versions  Next.js 16.2.0 up to 16.3.5 (Node.js runtime) 
Fixed in  Next.js 16.3.6 
Upstream dependency fix  Satori 0.33.5 
Security release for 15.x  Next.js 15.5.26 

Next.js 16.3.6 includes the security fix for CVE-2026-94545. 

Mitigation and Remediation Steps for Next.js Developers 

The complete fix is upgrading to a patched Next.js version. 

  • Upgrade to Next.js 16.3.6. Verify the resolved next/og and @vercel/og versions after the update, since the fix lives in the compiled artifacts. 
  • Audit your image-generation routes. Review every endpoint that renders through next/og, especially Open Graph routes that read query-string parameters and identify any untrusted value rendered inside SVG markup. 
  • Stop passing user input into SVG where you cannot patch immediately. As a temporary measure, do not place attacker-controlled values into SVG content, attributes, or styles processed by the Node.js ImageResponse implementation. 
  • Do not rely on input validation as a permanent fix. Complex SVG parsing and rendering behavior can open unexpected attack paths that validation misses. 

AppTrana WAAP Coverage for CVE-2026-94545   

AppTrana customers are protected against exploitation attempts targeting CVE-2026-94545, including malicious SVG payloads directed at next/og image-generation endpoints. 

Edge-level virtual patching blocks crafted input aimed at ImageResponse routes before it reaches the application, regardless of the Next.js version running underneath.  

AppTrana blocked this CVE-2026-94545 exploitation attempt, returning a 406 Not Acceptable when an encoded SVG payload was injected into the /og image-generation endpoint. 

AppTrana blocked the CVE-2026-94545 exploitation attempt, returning a 406 Not Acceptable

Bhargavi Pallati

Bhargavi Pallati is a Security Researcher at Indusface with experience in threat analysis, web application security, and detection engineering. She has a strong background as a Security Analyst and has worked extensively on vulnerability assessment and coverage verification. Bhargavi focuses on analyzing emerging attack patterns, strengthening application-level defenses, and improving security controls through continuous research and learning.