Critical Next.js Flaw CVE-2026-94545 Exposes Node.js to Code Execution, Urgent Update Advised

September 23, 2026
Critical Next.js Flaw CVE-2026-94545 Exposes Node.js to Code Execution, Urgent Update Advised
  • A security flaw, tracked as CVE-2026-94545, affects Next.js versions 16.2.0 through 16.3.5 on the Node.js runtime, while the Edge runtime is unaffected and Next.js 15 remains vulnerable.

  • Additional guidance covers how to verify affected versions and align with Satori’s advisory, outlining update paths and the varying impact based on SVG usage.

  • Developers should search their code for ImageResponse usage (imported from next/og) in route handlers or open-graph image files to identify implementations that may be affected.

  • Mitigation centers on ensuring attacker-controlled values are not embedded in SVG content, attributes, or styles, though there is no official recommendation to switch to the Edge runtime.

  • ImageResponse relies on Satori to translate image layouts into SVG before producing PNG, meaning attacker-controlled SVG content can trigger code execution.

  • The vulnerability in Next.js ImageResponse can enable server-side code execution when attacker-controlled values are embedded in SVG during image generation.

  • There is uncertainty about protection for hosted apps on Vercel, and Next.js documentation notes that the Edge runtime is deprecated.

  • As of publication, there were no public exploit reports, and npm audit did not flag 16.3.5 in checks; the CVE is being tracked, with related advisories from Satori.

  • Vercel released a fix in Next.js 16.3.6 on September 22, 2026; users on 16.2.x should upgrade to 16.3.6, and Next.js 15.5.26 adds additional hardening for next/og.

Summary based on 1 source


Get a daily email with more Tech stories

More Stories