Critical Next.js Flaw CVE-2026-94545 Exposes Node.js to Code Execution, Urgent Update Advised
September 23, 2026
A security flaw, tracked as CVE-2026-94545, affects Next.js versions 16.2.0 through 16.3.5 on the Node.js runtime, while the Edge runtime is unaffected and Next.js 15 remains vulnerable.
Additional guidance covers how to verify affected versions and align with Satori’s advisory, outlining update paths and the varying impact based on SVG usage.
Developers should search their code for ImageResponse usage (imported from next/og) in route handlers or open-graph image files to identify implementations that may be affected.
Mitigation centers on ensuring attacker-controlled values are not embedded in SVG content, attributes, or styles, though there is no official recommendation to switch to the Edge runtime.
ImageResponse relies on Satori to translate image layouts into SVG before producing PNG, meaning attacker-controlled SVG content can trigger code execution.
The vulnerability in Next.js ImageResponse can enable server-side code execution when attacker-controlled values are embedded in SVG during image generation.
There is uncertainty about protection for hosted apps on Vercel, and Next.js documentation notes that the Edge runtime is deprecated.
As of publication, there were no public exploit reports, and npm audit did not flag 16.3.5 in checks; the CVE is being tracked, with related advisories from Satori.
Vercel released a fix in Next.js 16.3.6 on September 22, 2026; users on 16.2.x should upgrade to 16.3.6, and Next.js 15.5.26 adds additional hardening for next/og.
Summary based on 1 source
Get a daily email with more Tech stories
Source

The Hacker News • Sep 23, 2026
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input