CVE-2026-94545: SVG-Serialization Markup Injection in Vercel Satori and Next.js ImageResponse
Vulnerability ID: GHSA-VCVR-R3JV-PC5J
CVSS Score: 9.8
Published: 2026-09-30
An improper output encoding and escaping vulnerability (CWE-116) in Vercel Satori allows unauthenticated remote attackers to perform markup injection in dynamic Open Graph images generated via Next.js's ImageResponse. Unsanitized parameter interpolation into SVG elements breaks XML structural boundaries. This exposes downstream parsing, rasterization, and rendering pipelines to Server-Side Request Forgery (SSRF), Local File Read, and Remote Code Execution (RCE).
TL;DR
Unsanitized user inputs passed to the Next.js ImageResponse wrapper are processed by the underlying Satori library without appropriate HTML/XML escaping. This allows attackers to break out of XML tag boundaries, inject arbitrary SVG nodes, and trigger downstream vulnerabilities in image-processing backends.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-116 (Improper Encoding or Escaping of Output)
- Attack Vector: Network (AV:N) / Unauthenticated Remote HTTP Request
- CVSS v4.0 Score: 9.8 (Critical Framework-Level Impact)
- EPSS Score: Not Available
- Exploit Status: Proof-of-Concept (PoC) documented and verified via rendering side-channel
- CISA KEV Status: No (Not currently listed in the CISA KEV catalog)
- Mitigation Strategy: Update Next.js or enforce strict input escaping and Edge runtime configurations
Affected Systems
- Next.js Node.js-runtime dynamic Open Graph image generation pipelines
- Serverless functions executing next/og ImageResponse APIs
- Custom Node.js applications consuming standalone Vercel Satori packages for HTML/CSS-to-SVG conversion
-
Next.js: >= 16.2.0, < 16.3.6 (Fixed in:
16.3.6) -
Satori: >= 0.0.27, < 0.33.5 (Fixed in:
0.33.5)
Code Analysis
Commit: 26a52af
Refactor Satori XML generation pipeline to implement strict validation, name assertions, HTML-escaping modules, and inline style controls
Commit: 868fad3
Pin and compile the patched @vercel/og bundle, resolve edge runtime compatibility conflicts, and update underlying Satori library definitions
Exploit Details
- GitHub: Verification lab containing vulnerable test servers and an automated python scanner utilizing a PNG rendering side-channel decoding script
Mitigation Strategies
- Upgrade Next.js dependencies to version 16.3.6 or higher (or backported version 15.5.26)
- Upgrade standalone Vercel Satori packages to version 0.33.5 or higher
- Configure dynamic ImageResponse routes to execute inside the Edge Runtime
- Implement a strict string-sanitization middleware to escape XML entities in input parameters before rendering
Remediation Steps:
- Identify all API and dynamic page files utilizing 'next/og' or direct Satori rendering
- Run 'npm install next@16.3.6' or 'yarn add next@16.3.6' to pull the patched dependency bundle
- Validate the package-lock.json or yarn.lock file to ensure Satori is resolved to 0.33.5 or higher
- If packages cannot be updated, implement the 'sanitizeForSVG' helper on all dynamic parameters
- Add 'export const runtime = "edge"' to the top of dynamic OG image generation routes
- Deploy the updated application and perform a non-destructive side-channel verification scan to ensure input parameters are properly escaped
References
- Next.js Security Advisory GHSA-vcvr-r3jv-pc5j
- Satori Security Advisory GHSA-wx4j-mvgx-mqwp
- Satori Patch Commit 26a52affc
- Next.js Patch Commit 868fad3
- Satori Core Serialization PR 814
- Next.js v16.3.6 Release Tags
- Next.js Security Blog Update September 2026
- Netlify Customer Advisory on ImageResponse vulnerability
- Hassham1 CVE-2026-94545 next/og loopback test lab and scanner
Read the full report for GHSA-VCVR-R3JV-PC5J on our website for more details including interactive diagrams and full exploit analysis.
Top comments (2)
Some comments may only be visible to logged-in visitors. Sign in to view all comments.