DEV Community

Cover image for Vercel Patches Critical Remote Code Execution Vulnerability in Next.js Image Generation Feature
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Vercel Patches Critical Remote Code Execution Vulnerability in Next.js Image Generation Feature

Summary

Vercel patched a critical vulnerability (CVE-2026-94545) in Next.js that allows remote code execution through the ImageResponse feature. The flaw involves improper input escaping in the Satori library when processing SVG content on the Node.js runtime.

Take Action:

If your web apps run Next.js 16 (versions 16.2.0 to 16.3.5), update to 16.3.6 ASAP. Don't rely on dependency scanners to flag this one, because they may miss it. If you can't update right away, make sure your developers sanitize up all user input before it reaches the social preview image feature (ImageResponse).


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)