Vercel has patched a critical vulnerability in Next.js's ImageResponse feature, which generates Open Graph and social preview images. Tracked as CVE-2026-94545, the flaw allows attackers to execute arbitrary code on a server when an application passes attacker-controlled values—such as text from a request URL—into SVG content, attributes, or styles during image generation. The issue affects Next.js versions 16.2.0 through 16.3.5 when ImageResponse runs on the Node.js runtime, which is the default. The fix is available in version 16.3.6, released September 22.
The root cause lies in Satori, a Vercel library that converts image layouts into SVG code. Satori's advisory says certain values reached its SVG output without proper escaping, allowing specially crafted input to be interpreted as SVG code instead of plain text. In Next.js, this could chain into vulnerabilities in other dependencies, leading to code execution. Vercel rates the flaw as critical with a CVSS score of 9.5, while Satori's own advisory rates it moderate (5.3), noting the impact depends on how the SVG output is used. The Edge runtime version of ImageResponse is not affected, but Vercel does not recommend switching to it because the Edge runtime is deprecated.
As of September 23, no public exploits or attack reports have surfaced, and no exploit code is available. However, The Hacker News notes that npm audit did not flag the affected version 16.3.5, and the advisory was not yet listed in the GitHub Advisory Database, so developers must check their Next.js version directly. The workaround, if upgrading is delayed, is to keep attacker-controlled values out of SVG content, attributes, and styles. Apps on Next.js 16.2 must move to 16.3.6, as no fixed release exists for that line. Next.js 15.5.26 adds extra hardening for next/og on the 15.5 line, but the only fully patched version is 16.3.6.