DEV Community

kozhevniko
kozhevniko

Posted on

CVE-2026-94545 Exploitability Deep Dive: Escaping, Native Parsing and the Non-PIE Node Build

CVE-2026-94545 Exploitability Deep Dive: Escaping, Native Parsing and the Non-PIE Node Build

Vulnerability overview

CVE-2026-94545 is a remote code execution vulnerability in the Next.js next/og route. Satori produces SVG from JSX and embeds user text without escaping it. Public exploitation details exist, and the flaw is fixed in Next.js 16.3.6 and Satori 0.33.5.

Stage one: escaping failure in the renderer

Satori turns JSX into SVG. When application code passes attacker influenced values into the rendered image, those values land in the SVG document as text. Because they are not escaped, an attacker can close the enclosing element and open attacker markup instead. Everything after that point operates on content the attacker controls.
This stage alone would be a document injection issue. The severity comes from what happens next.

Stage two: native parsing and memory corruption

On the Node.js runtime with sharp installed, the generated SVG is not treated as inert markup. It is handed to native libraries, including libvips and libxml2, for rasterisation. EQSTLab found that crafted XML entities corrupt memory inside that parser.

Stage three: why the non-PIE build matters

Memory corruption usually demands an address leak before control flow can be redirected. The official Node binary is built without position independent executables, so its addresses stay fixed across runs. That removes the leak requirement and makes a working exploit portable across hosts running the same build. It is also why the technique is described as needing no address disclosure.
The practical consequence for defenders is that mitigations which assume address randomisation carry less weight here.

Impact

Successful exploitation gives code execution as the Node.js process. The attack is blind and crashes the worker, so operators would pair it with a reverse shell to observe output, which makes egress control a meaningful mitigation.

Affected products and scope

Satori 0.0.27 up to but not including 0.33.5, and Next.js 16.2.0 through 16.3.5 on the Node.js runtime with sharp. Edge runtime deployments and installations without sharp use a sandboxed renderer where this chain does not complete.

Exposure context

ZoomEye returns 1,733,654 assets for app="Next.js" and 0 for vul.cve="CVE-2026-94545". Product exposure is broad; CVE-indexed exposure is absent. Neither number indicates how many instances combine Node, sharp and an exposed image route.

Remediation and mitigations

Upgrade to Next.js 16.3.6 and Satori 0.33.5. If patching is delayed, switch next/og to the Edge runtime or remove sharp so the native parser is not involved, and keep untrusted values out of ImageResponse. Restrict outbound traffic to blunt the reverse shell step.

References

Top comments (0)