CVE-2026-94545
Satori SVG injection affecting Next.js ImageResponse
NVD scores the Satori issue 5.3. Vercel says the Node.js next/og ImageResponse path can lead to code execution when attacker-controlled values are written into SVG. Fixed in Next.js 16.3.6. A public PoC repository exists. The score 9.5 is not in either advisory.
- CVSS
- 5.3
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
- Class
- RCE
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Vercel
- Products
- Satori, Next.js
- Affected
- Satori from 0.0.27 before 0.33.5. Next.js from 16.2.0 before 16.3.6, on the Node.js ImageResponse implementation, when attacker-controlled values are passed into SVG content, attributes, or styles. The Edge ImageResponse implementation is not affected.
- Fixed
- Satori 0.33.5. Next.js 16.3.6.
- CWE
- CWE-116
- Published
- 30 Sept 2026
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-94545 is filed against Satori, the library that turns HTML and CSS into SVG. From version 0.0.27 before 0.33.5, some values are not escaped before they are placed in generated SVG, so crafted input can be read as markup. NVD scores that issue 5.3 Medium under CVSS 4.0, with CWE-116. The vector needs a user and an attack requirement, and the high impact is on the subsequent system, not on Satori itself.
Vercel's Next.js advisory, GHSA-vcvr-r3jv-pc5j, says the Node.js implementation of ImageResponse in next/og is affected and that this can lead to remote code execution. Vercel labels that advisory critical and does not publish a numeric score. The range is Next.js 16.2.0 up to, but not including, 16.3.6. Applications that do not pass attacker-controlled values into SVG content, attributes, or styles are outside the vulnerable condition. The Edge implementation of ImageResponse is not affected. Next.js 16.3.6, published on 22 September 2026, contains the fix.
A public repository appeared on 29 September 2026. ThreatWire marks PoC Available. It is not in the CISA KEV catalog, and the fix predates that repository, so this is not a 0-day. A score of 9.5 does not appear in the NVD entry or in the Next.js advisory. ThreatWire does not republish the proof-of-concept input.