A significant security vulnerability has been identified in Next.js, potentially enabling attackers to execute code on a server through the ImageResponse feature. This feature is utilized to generate Open Graph and other social preview images. The flaw is particularly concerning when an application incorporates user-controlled values, such as text from a request URL, into its image generation process. Vercel, the developer behind Next.js, addressed this flaw on September 22 with the release of version 16.3.6.

The issue, tracked under CVE-2026-94545, affects versions 16.2.0 through 16.3.5 of Next.js when ImageResponse operates on the Node.js runtime. The severity of this flaw is rated as critical, with a CVSS score of 9.5. Notably, the Edge version of ImageResponse and Next.js 15 are not impacted.

ImageResponse leverages Satori, a Vercel library, to convert image layouts into SVG code prior to generating the final PNG. Applications that allow attacker-controlled values to be incorporated into SVG content, attributes, or styles during image generation are at risk. The advisory illustrates the vulnerability with an example involving a request URL value being placed inside an SVG title element.

To identify vulnerable instances, developers should look for ImageResponse imported from next/og, particularly in route handlers and opengraph-image files. As of September 23, no public exploits or reported attacks have been associated with this vulnerability.

The recommended solution is to upgrade to Next.js 16.3.6 using npm install [email protected]. For those unable to upgrade immediately, a temporary workaround involves preventing attacker-controlled values from entering the SVG content rendered by Node.js ImageResponse. Although switching to the unaffected Edge version is not recommended due to its deprecated status, developers should consider updating Satori directly to version 0.33.5 if it is used independently.

Vercel has not confirmed whether applications hosted on its platform are protected by default, nor is there a way to determine if affected routes were compromised prior to the patch. The underlying bug exists in Satori, where certain values were not properly escaped, causing them to be interpreted as SVG code instead of plain text. Satori's advisory assigns a moderate severity rating to the issue, dependent on the usage of the SVG output.