Skip to content
Critical Vulnerability in Next.js ImageResponse Allows Remote Code Execution

Critical Vulnerability in Next.js ImageResponse Allows Remote Code Execution

First seen 23 Sep 2026, 10:59 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 11:57 UTC
  • CVE-2026-94545 allows remote code execution in Next.js versions 16.2.0 to 16.3.5.
  • The vulnerability is rated critical with a CVSS score of 9.5 and was patched in version 16.3.6.
  • No public exploits have been reported as of September 23, 2026.

A critical vulnerability in Next.js, tracked as CVE-2026-94545, allows remote code execution via the ImageResponse feature when attacker-controlled values are included in SVG content. The flaw affects versions 16.2.0 through 16.3.5 and was fixed in version 16.3.6 released on September 22, 2026. Vercel, the developer of Next.js, rated the vulnerability with a CVSS score of 9.5, indicating its critical nature. The Edge version of ImageResponse and Next.js 15.x are not affected. As of September 23, no public exploits or attacks have been reported, but users are advised to upgrade immediately or implement workarounds to mitigate risks. The vulnerability stems from improper escaping in SVG output generated by the Satori library, which is bundled with Next.js. The advisory emphasizes the need to avoid using attacker-controlled values in SVG content.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
Patch for Next.js released
Vercel released Next.js version 16.3.6 to address the critical vulnerability CVE-2026-94545.
Nextjs
2026-09-23
Vulnerability details published
The Hacker News reported on the critical vulnerability in Next.js ImageResponse and its implications.
Thehackernews

More articles in this cluster (2)

Following this threat?

Track CVE-2026-94545 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed