A serious vulnerability has been discovered in Next.js that allows remote code execution in applications using its Node.js ImageResponse implementation. Tracked as GHSA-vcvr-r3jv-pc5j, the flaw impacts Next.js versions 16.2.0 through 16.3.5. The security issue has been addressed in version 16.3.6. Applications using the Edge ImageResponse implementation are not affected. The core problem arises when user-supplied data gets injected into SVG content, attributes, or styles without sufficient sanitation. Malicious payloads in these contexts can bypass escaping and execute arbitrary code through the underlying rendering engine.
How the Vulnerability Works
The vulnerability occurs in ImageResponse requests that incorporate attacker-controlled input into SVG markup—for example, placing untrusted values into SVG
Underlying the issue is a flaw in Satori, the SVG generation library used by Next.js for rendering these dynamic graphics. Versions from 0.0.27 through 0.33.4 of Satori are affected by CVE-2026-94545 and GHSA-wx4j-mvgx-mqwp. This upstream defect permitted improperly escaped content to be processed as valid SVG markup. The patch in Satori came with version 0.33.5.
Risk, Scope, and Mitigation Steps
The issue is rated critical under CVSS v4. The advisory notes that it allows exploitation over the network, with low complexity and no need for special privileges or user interaction. Confidentiality, integrity, and availability of both the application and downstream systems could be compromised. Vulnerable paths include any ImageResponse endpoint that processes external input from URL parameters, headers, CMS content, profile names, or post content.
To protect against the vulnerability, developers should upgrade Next.js to version 16.3.6 immediately. If upgrading isn’t possible right away, avoid placing attacker-controlled data inside SVG markup, attributes, or style properties in Node.js ImageResponse routes. Edge implementation can be a safe alternative, though teams must test behavior carefully before switching. Auditing all image-generation endpoints for untrusted input handling is strongly advised.
The advisory credits the security researchers who reported the issue. Given how severe this flaw is—allowing unauthenticated remote code execution—organizations with affected deployments are urged to treat this patch as high priority.
This vulnerability continues a concerning pattern of flaws in dynamic content generation and image rendering. With AI and real-time graphics generation on the rise, this kind of oversight in input sanitization has become increasingly dangerous. Developers and security teams should watch for similar vector issues beyond SVGs, especially in environments that process user input into rendered content. Ensuring proper escaping, using safe rendering modes like the Edge implementation, and keeping dependencies like Satori up to date are key defenses.