Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
Read original article ↗AI Summary
A critical vulnerability in Next.js, tracked as CVE-2026-94545, allows server-side code execution when attacker-controlled input is processed by the ImageResponse feature during SVG generation. The flaw exists in versions 16.2.0 through 16.3.5 when using the Node.js runtime, where unsanitized input can be interpreted as SVG code due to improper escaping in the underlying Satori library. This could enable remote attackers to execute arbitrary code on the server if user-supplied values are embedded in SVG content, attributes, or styles. The vulnerability was patched in Next.js 16.3.6 and Satori 0.33.5, with no public exploits or active attacks reported at the time of disclosure.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.