Summary
Vercel patched a critical vulnerability (CVE-2026-94545) in Next.js that allows remote code execution through the ImageResponse feature. The flaw involves improper input escaping in the Satori library when processing SVG content on the Node.js runtime.
Take Action:
If your web apps run Next.js 16 (versions 16.2.0 to 16.3.5), update to 16.3.6 ASAP. Don't rely on dependency scanners to flag this one, because they may miss it. If you can't update right away, make sure your developers sanitize up all user input before it reaches the social preview image feature (ImageResponse).
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)