An out-of-band security update is now available in v16.3.6 (Active LTS) and v15.5.26 (Maintenance LTS). These releases upgrade upstream dependencies, including Satori, to address an issue that could lead to remote code execution in affected .js versions. Version 15.5.26 includes related hardening, but .js 15.x is not affected by the remote code execution issue.
Please patch your .js dependencies to maintain the security of your applications.
Remote Code Execution in Node.js ImageResponse (Critical Severity)
GHSA-vcvr-r3jv-pc5j ( .js)
Related upstream advisory: GHSA-wx4j-mvgx-mqwp (Satori)
.js versions >=16.2.0 <16.3.6 are affected.
The issue affects the Node.js ImageResponse implementation in /og . Under specific conditions, improper escaping in SVG output generated by Satori could lead to remote code execution due to vulnerabilities in other upstream dependencies. The fix upgrades those dependencies.
Applications using the Edge ImageResponse implementation are not affected.
We work with a talented set of researchers to secure .js and other open source frameworks through Vercel's Open Source Bug Bounty . Anyone interested in contributing to the security of eligible frameworks is encouraged to participate there.
Any questions or concerns regarding our security programs or vulnerability management can be sent to [email protected] .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
