Critical Next.js Flaw in ImageResponse Lets Attackers Run Remote Code

A serious vulnerability has been discovered in Next.js that allows remote code execution in applications using its Node.js ImageResponse implementation. Tracked as GHSA-vcvr-r3jv-pc5j, the flaw impacts Next.js versions 16.2.0 through 16.3.5. The security issue has been addressed in version 16.3.6. Applications using the Edge ImageResponse implementation are not affected. The core problem arises when user-supplied data gets injected into SVG content, attributes, or styles without sufficient sanitation. Malicious payloads in these contexts can bypass escaping and execute arbitrary code through the underlying rendering engine.

How the Vulnerability Works

The vulnerability occurs in ImageResponse requests that incorporate attacker-controlled input into SVG markup—for example, placing untrusted values into SVG tags or style attributes. When such input isn’t properly escaped, it reaches the library that generates the SVG, enabling crafted strings to be interpreted as markup. This lets attackers potentially exploit remote image-generation endpoints, especially those exposed to the internet, such as Open Graph preview routes. </p> <p>Underlying the issue is a flaw in Satori, the SVG generation library used by Next.js for rendering these dynamic graphics. Versions from 0.0.27 through 0.33.4 of Satori are affected by CVE-2026-94545 and GHSA-wx4j-mvgx-mqwp. This upstream defect permitted improperly escaped content to be processed as valid SVG markup. The patch in Satori came with version 0.33.5. </p> <h2>Risk, Scope, and Mitigation Steps</h2> <p>The issue is rated critical under CVSS v4. The advisory notes that it allows exploitation over the network, with low complexity and no need for special privileges or user interaction. Confidentiality, integrity, and availability of both the application and downstream systems could be compromised. Vulnerable paths include any ImageResponse endpoint that processes external input from URL parameters, headers, CMS content, profile names, or post content. </p> <p>To protect against the vulnerability, developers should upgrade Next.js to version 16.3.6 immediately. If upgrading isn’t possible right away, avoid placing attacker-controlled data inside SVG markup, attributes, or style properties in Node.js ImageResponse routes. Edge implementation can be a safe alternative, though teams must test behavior carefully before switching. Auditing all image-generation endpoints for untrusted input handling is strongly advised. </p> <p>The advisory credits the security researchers who reported the issue. Given how severe this flaw is—allowing unauthenticated remote code execution—organizations with affected deployments are urged to treat this patch as high priority. </p> <p>This vulnerability continues a concerning pattern of flaws in dynamic content generation and image rendering. With AI and real-time graphics generation on the rise, this kind of oversight in input sanitization has become increasingly dangerous. Developers and security teams should watch for similar vector issues beyond SVGs, especially in environments that process user input into rendered content. Ensuring proper escaping, using safe rendering modes like the Edge implementation, and keeping dependencies like Satori up to date are key defenses.</p> </div><!-- .entry-content --> <footer class="entry-footer"> <span class="cat-links">Posted in <a href="https://thedailytechfeed.com/category/security/" rel="category tag">Cybersecurity News</a></span> </footer><!-- .entry-footer --> </article><!-- #post-55039 --> <nav class="navigation post-navigation" aria-label="Posts"> <h2 class="screen-reader-text">Post navigation</h2> <div class="nav-links"><div class="nav-previous"><a href="https://thedailytechfeed.com/attackers-slip-malware-past-microsoft-defender-using-hidden-exclusions/" rel="prev"><span class="nav-subtitle">Previous:</span> <span class="nav-title">Attackers Slip Malware Past Microsoft Defender Using Hidden Exclusions</span></a></div><div class="nav-next"><a href="https://thedailytechfeed.com/audible-adds-ai-powered-features-explore-stories-talk-to-characters/" rel="next"><span class="nav-subtitle">Next:</span> <span class="nav-title">Audible adds AI-powered features: explore stories, talk to characters</span></a></div></div> </nav> <div class="related-posts"> <h2>Related Posts</h2> <div class="theme-archive-layout grid-layout grid-column-3"> <article id="post-54750" class="post-54750 post type-post status-publish format-standard has-post-thumbnail hentry category-security"> <div class="post-item post-grid"> <div class="post-item-image"> <div class="post-thumbnail"> <img width="1024" height="1024" src="https://thedailytechfeed.com/wp-content/uploads/2026/09/7636.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://thedailytechfeed.com/wp-content/uploads/2026/09/7636.png 1024w, https://thedailytechfeed.com/wp-content/uploads/2026/09/7636-300x300.png 300w, https://thedailytechfeed.com/wp-content/uploads/2026/09/7636-150x150.png 150w, https://thedailytechfeed.com/wp-content/uploads/2026/09/7636-768x768.png 768w" sizes="(max-width: 1024px) 100vw, 1024px" /> </div><!-- .post-thumbnail --> </div> <div class="post-item-content"> <div class="entry-cat no-bg"> <ul class="post-categories"> <li><a href="https://thedailytechfeed.com/category/security/" rel="category tag">Cybersecurity News</a></li></ul> </div> <h2 class="entry-title"><a href="https://thedailytechfeed.com/malware-uses-ethereum-to-hide-command-servers-in-plain-sight/" rel="bookmark">Malware Uses Ethereum to Hide Command Servers in Plain Sight</a></h2> <ul class="entry-meta"> <li class="post-author"> <a href="https://thedailytechfeed.com/author/uqlmj/">The Daily Tech Feed Team</a></li> <li class="post-date"> <span class="far fa-calendar-alt"></span>September 29, 2026</li> <li class="post-comment"> <span class="far fa-comment"></span>0</li> </ul> <div class="post-content"> <p>Security researchers have uncovered a clever new tactic in a malware campaign backed by North Korea, in which attackers hide the location of their command-and-control […]</p> </div><!-- post-content --> </div> </div> </article> <article id="post-34885" class="post-34885 post type-post status-publish format-standard has-post-thumbnail hentry category-security"> <div class="post-item post-grid"> <div class="post-item-image"> <div class="post-thumbnail"> <img width="728" height="380" src="https://thedailytechfeed.com/wp-content/uploads/2026/04/65-7.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://thedailytechfeed.com/wp-content/uploads/2026/04/65-7.jpg 728w, https://thedailytechfeed.com/wp-content/uploads/2026/04/65-7-300x157.jpg 300w" sizes="(max-width: 728px) 100vw, 728px" /> </div><!-- .post-thumbnail --> </div> <div class="post-item-content"> <div class="entry-cat no-bg"> <ul class="post-categories"> <li><a href="https://thedailytechfeed.com/category/security/" rel="category tag">Cybersecurity News</a></li></ul> </div> <h2 class="entry-title"><a href="https://thedailytechfeed.com/project-glasswing-reveals-ais-bug-detection-power-highlights-cybersecurity-remediation-challenges/" rel="bookmark">Project Glasswing Reveals AI’s Bug Detection Power, Highlights Cybersecurity Remediation Challenges</a></h2> <ul class="entry-meta"> <li class="post-author"> <a href="https://thedailytechfeed.com/author/uqlmj/">The Daily Tech Feed Team</a></li> <li class="post-date"> <span class="far fa-calendar-alt"></span>April 24, 2026</li> <li class="post-comment"> <span class="far fa-comment"></span>0</li> </ul> <div class="post-content"> <p>Project Glasswing Unveils AI’s Power in Bug Detection—But Who Will Fix Them? Anthropic’s recent unveiling of Project Glasswing has sent shockwaves through the cybersecurity community. […]</p> </div><!-- post-content --> </div> </div> </article> <article id="post-43513" class="post-43513 post type-post status-publish format-standard has-post-thumbnail hentry category-security"> <div class="post-item post-grid"> <div class="post-item-image"> <div class="post-thumbnail"> <img width="1024" height="1024" src="https://thedailytechfeed.com/wp-content/uploads/2026/07/1955.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://thedailytechfeed.com/wp-content/uploads/2026/07/1955.png 1024w, https://thedailytechfeed.com/wp-content/uploads/2026/07/1955-300x300.png 300w, https://thedailytechfeed.com/wp-content/uploads/2026/07/1955-150x150.png 150w, https://thedailytechfeed.com/wp-content/uploads/2026/07/1955-768x768.png 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /> </div><!-- .post-thumbnail --> </div> <div class="post-item-content"> <div class="entry-cat no-bg"> <ul class="post-categories"> <li><a href="https://thedailytechfeed.com/category/security/" rel="category tag">Cybersecurity News</a></li></ul> </div> <h2 class="entry-title"><a href="https://thedailytechfeed.com/xalgorix-ai-powered-penetration-testing-with-22-phase-methodology/" rel="bookmark">Xalgorix: AI-Powered Penetration Testing with 22-Phase Methodology</a></h2> <ul class="entry-meta"> <li class="post-author"> <a href="https://thedailytechfeed.com/author/uqlmj/">The Daily Tech Feed Team</a></li> <li class="post-date"> <span class="far fa-calendar-alt"></span>July 10, 2026</li> <li class="post-comment"> <span class="far fa-comment"></span>0</li> </ul> <div class="post-content"> <p>Xalgorix is an open-source, self-hosted AI penetration testing platform that employs an autonomous large language model (LLM) agent alongside an independent exploit verifier to deliver […]</p> </div><!-- post-content --> </div> </div> </article> </div> </div> </main><!-- #main --> <aside id="secondary" class="widget-area"> <section id="block-2" class="widget widget_block widget_search"></section><section id="block-9" class="widget widget_block widget_calendar"><div class="wp-block-calendar"><table id="wp-calendar" class="wp-calendar-table"> <caption>October 2026</caption> <thead> <tr> <th scope="col" aria-label="Monday">M</th> <th scope="col" aria-label="Tuesday">T</th> <th scope="col" aria-label="Wednesday">W</th> <th scope="col" aria-label="Thursday">T</th> <th scope="col" aria-label="Friday">F</th> <th scope="col" aria-label="Saturday">S</th> <th scope="col" aria-label="Sunday">S</th> </tr> </thead> <tbody> <tr> <td colspan="3" class="pad"> </td><td><a href="https://thedailytechfeed.com/2026/10/01/" aria-label="Posts published on October 1, 2026">1</a></td><td><a href="https://thedailytechfeed.com/2026/10/02/" aria-label="Posts published on October 2, 2026">2</a></td><td><a href="https://thedailytechfeed.com/2026/10/03/" aria-label="Posts published on October 3, 2026">3</a></td><td id="today"><a href="https://thedailytechfeed.com/2026/10/04/" aria-label="Posts published on October 4, 2026">4</a></td> </tr> <tr> <td>5</td><td>6</td><td>7</td><td>8</td><td>9</td><td>10</td><td>11</td> </tr> <tr> <td>12</td><td>13</td><td>14</td><td>15</td><td>16</td><td>17</td><td>18</td> </tr> <tr> <td>19</td><td>20</td><td>21</td><td>22</td><td>23</td><td>24</td><td>25</td> </tr> <tr> <td>26</td><td>27</td><td>28</td><td>29</td><td>30</td><td>31</td> <td class="pad" colspan="1"> </td> </tr> </tbody> </table><nav aria-label="Previous and next months" class="wp-calendar-nav"> <span class="wp-calendar-nav-prev"><a href="https://thedailytechfeed.com/2026/09/">« Sep</a></span> <span class="pad"> </span> <span class="wp-calendar-nav-next"> </span> </nav></div></section><section id="block-13" class="widget widget_block widget_archive"><ul class="wp-block-archives-list wp-block-archives"> <li><a href='https://thedailytechfeed.com/2026/10/'>October 2026</a></li> <li><a href='https://thedailytechfeed.com/2026/09/'>September 2026</a></li> <li><a href='https://thedailytechfeed.com/2026/08/'>August 2026</a></li> <li><a href='https://thedailytechfeed.com/2026/07/'>July 2026</a></li> <li><a href='https://thedailytechfeed.com/2026/06/'>June 2026</a></li> <li><a href='https://thedailytechfeed.com/2026/05/'>May 2026</a></li> <li><a href='https://thedailytechfeed.com/2026/04/'>April 2026</a></li> <li><a href='https://thedailytechfeed.com/2026/03/'>March 2026</a></li> <li><a href='https://thedailytechfeed.com/2026/02/'>February 2026</a></li> <li><a href='https://thedailytechfeed.com/2026/01/'>January 2026</a></li> <li><a href='https://thedailytechfeed.com/2025/12/'>December 2025</a></li> <li><a href='https://thedailytechfeed.com/2025/11/'>November 2025</a></li> <li><a href='https://thedailytechfeed.com/2025/10/'>October 2025</a></li> <li><a href='https://thedailytechfeed.com/2025/09/'>September 2025</a></li> <li><a href='https://thedailytechfeed.com/2025/08/'>August 2025</a></li> <li><a href='https://thedailytechfeed.com/2025/07/'>July 2025</a></li> <li><a href='https://thedailytechfeed.com/2025/06/'>June 2025</a></li> <li><a href='https://thedailytechfeed.com/2025/05/'>May 2025</a></li> <li><a href='https://thedailytechfeed.com/2025/04/'>April 2025</a></li> <li><a href='https://thedailytechfeed.com/2025/03/'>March 2025</a></li> <li><a href='https://thedailytechfeed.com/2025/02/'>February 2025</a></li> </ul></section></aside><!-- #secondary --> </div> </div> </div><!-- #content --> <footer id="colophon" class="site-footer"> <div class="top-footer"> <div class="theme-wrapper"> <div class="top-footer-widgets"> <div class="footer-widget"> </div> <div class="footer-widget"> </div> <div class="footer-widget"> </div> <div class="footer-widget"> <section id="block-14" class="widget widget_block"><a rel="me" href="https://mastodon.social/@dailytechfeed">Mastodon</a></section> </div> </div> </div> </div> <div class="bottom-footer"> <div class="theme-wrapper"> <div class="bottom-footer-info"> <div class="site-info"> <span>Copyright © 2026 <a href="https://thedailytechfeed.com/">The Daily Tech Feed</a></span> </div><!-- .site-info --> </div> </div> </div> </footer><!-- #colophon --> <a href="#" id="scroll-to-top" class="hot-news-pro-scroll-to-top"><i class="fas fa-chevron-up"></i></a> </div><!-- #page --> <script type="speculationrules"> {"prefetch":[{"source":"document","where":{"and":[{"href_matches":"/*"},{"not":{"href_matches":["/wp-*.php","/wp-admin/*","/wp-content/uploads/*","/wp-content/*","/wp-content/plugins/*","/wp-content/themes/hot-news-pro-premium/*","/*\\?(.+)"]}},{"not":{"selector_matches":"a[rel~=\"nofollow\"]"}},{"not":{"selector_matches":".no-prefetch, .no-prefetch a"}}]},"eagerness":"conservative"}]} </script> <script id="hot-news-pro-navigation-js" src="https://thedailytechfeed.com/wp-content/themes/hot-news-pro-premium/assets/js/navigation.min.js?ver=1.0.1"></script> <script id="hot-news-pro-slick-script-js" src="https://thedailytechfeed.com/wp-content/themes/hot-news-pro-premium/assets/js/slick.min.js?ver=1.8.1"></script> <script id="hot-news-pro-endless-river-script-js" src="https://thedailytechfeed.com/wp-content/themes/hot-news-pro-premium/assets/js/endless-river.min.js?ver=1.8.0"></script> <script id="hot-news-pro-custom-script-js" src="https://thedailytechfeed.com/wp-content/themes/hot-news-pro-premium/assets/js/custom.min.js?ver=1.0.1"></script> <script id="googlesitekit-events-provider-content-events-js-before"> window._googlesitekit = window._googlesitekit || {}; window._googlesitekit.contentEvents = {"postID":55039,"isSinglePost":true,"hasVimeoEmbed":false}; //# sourceURL=googlesitekit-events-provider-content-events-js-before </script> <script id="googlesitekit-events-provider-content-events-js" src="https://thedailytechfeed.com/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-content-events-c7172f3fd0e4d5ad62ef.js" defer></script> <script id="wp-emoji-settings" type="application/json"> {"baseUrl":"https://s.w.org/images/core/emoji/17.0.2/72x72/","ext":".png","svgUrl":"https://s.w.org/images/core/emoji/17.0.2/svg/","svgExt":".svg","source":{"concatemoji":"https://thedailytechfeed.com/wp-includes/js/wp-emoji-release.min.js?ver=7.1.2"}} </script> <script type="module"> /*! This file is auto-generated */ var e="script#wp-emoji-settings",t=document.querySelector(e);if(!(t instanceof HTMLScriptElement))throw new Error("Element missing: "+e);const r=JSON.parse(t.text),s=(window._wpemojiSettings=r,"wpEmojiSettingsSupports"),o=["flag","emoji"];function i(e){try{var t={supportTests:e,timestamp:(new Date).valueOf()};sessionStorage.setItem(s,JSON.stringify(t))}catch(e){}}function c(e,t,n){e.clearRect(0,0,e.canvas.width,e.canvas.height),e.fillText(t,0,0);t=new Uint32Array(e.getImageData(0,0,e.canvas.width,e.canvas.height).data);e.clearRect(0,0,e.canvas.width,e.canvas.height),e.fillText(n,0,0);const r=new Uint32Array(e.getImageData(0,0,e.canvas.width,e.canvas.height).data);return t.every((e,t)=>e===r[t])}function p(e,t){e.clearRect(0,0,e.canvas.width,e.canvas.height),e.fillText(t,0,0);var n=e.getImageData(16,16,1,1);for(let e=0;e<n.data.length;e++)if(0!==n.data[e])return!1;return!0}function u(e,t,n,r){switch(t){case"flag":return n(e,"\ud83c\udff3\ufe0f\u200d\u26a7\ufe0f","\ud83c\udff3\ufe0f\u200b\u26a7\ufe0f")?!1:!n(e,"\ud83c\udde8\ud83c\uddf6","\ud83c\udde8\u200b\ud83c\uddf6")&&!n(e,"\ud83c\udff4\udb40\udc67\udb40\udc62\udb40\udc65\udb40\udc6e\udb40\udc67\udb40\udc7f","\ud83c\udff4\u200b\udb40\udc67\u200b\udb40\udc62\u200b\udb40\udc65\u200b\udb40\udc6e\u200b\udb40\udc67\u200b\udb40\udc7f");case"emoji":return!r(e,"\ud83e\u1fac8")}return!1}function f(e,t,n,r){let a;const s=(a="undefined"!=typeof WorkerGlobalScope&&self instanceof WorkerGlobalScope?new OffscreenCanvas(300,150):document.createElement("canvas")).getContext("2d",{willReadFrequently:!0}),o=(s.textBaseline="top",s.font="600 32px Arial",{});return e.forEach(e=>{o[e]=t(s,e,n,r)}),o}function a(e){var t=document.createElement("script");t.src=e,t.defer=!0,document.head.appendChild(t)}r.supports={everything:!0,everythingExceptFlag:!0},new Promise(t=>{let n=function(){try{var e=JSON.parse(sessionStorage.getItem(s));if("object"==typeof e&&"number"==typeof e.timestamp&&(new Date).valueOf()<e.timestamp+604800&&"object"==typeof e.supportTests)return e.supportTests}catch(e){}return null}();if(!n){if("undefined"!=typeof Worker&&"undefined"!=typeof OffscreenCanvas&&"undefined"!=typeof URL&&URL.createObjectURL&&"undefined"!=typeof Blob)try{var e="postMessage("+f.toString()+"("+[JSON.stringify(o),u.toString(),c.toString(),p.toString()].join(",")+"));",r=new Blob([e],{type:"text/javascript"});const a=new Worker(URL.createObjectURL(r),{name:"wpTestEmojiSupports"});return void(a.onmessage=e=>{i(n=e.data),a.terminate(),t(n)})}catch(e){}i(n=f(o,u,c,p))}t(n)}).then(e=>{for(const n in e)r.supports[n]=e[n],r.supports.everything=r.supports.everything&&r.supports[n],"flag"!==n&&(r.supports.everythingExceptFlag=r.supports.everythingExceptFlag&&r.supports[n]);var t;r.supports.everythingExceptFlag=r.supports.everythingExceptFlag&&!r.supports.flag,r.supports.everything||((t=r.source||{}).concatemoji?a(t.concatemoji):t.wpemoji&&t.twemoji&&(a(t.twemoji),a(t.wpemoji)))}); //# sourceURL=https://thedailytechfeed.com/wp-includes/js/wp-emoji-loader.min.js </script> </body> </html>