Skip to content
THREATWIRE

Research

Reading the Next.js ImageResponse advisory

CVE-2026-94545 is a Satori escaping bug that Vercel says can become code execution in Node.js next/og. The only published numeric score is 5.3. Next.js 16.3.6 is the fix. A public PoC exists.

Critical

Published 5 Oct 2026 · Updated 5 Oct 2026

What happened

CVE-2026-94545 starts in Satori, the library that turns HTML and CSS into SVG. From 0.0.27 up to, but not including, 0.33.5, some values are written into the generated SVG without proper escaping. Crafted values can be read as markup. CWE-116 is the weakness NVD records. The CVE text says the damage depends on whatever consumes that SVG.

Next.js sits on that path when an application uses the Node.js ImageResponse from next/og. Vercel advisory GHSA-vcvr-r3jv-pc5j, published 22 September 2026, says that case can become remote code execution. The Next.js range is 16.2.0 through every version before 16.3.6.

Who is affected

Two products share the CVE record, and they are not the same deployment. A direct dependency on Satori in the vulnerable range is the library bug. A Next.js application is in the Vercel advisory only when it is on 16.2.0 or newer, older than 16.3.6, and it passes attacker-controlled values into SVG content, attributes, or styles while generating an image.

The Edge ImageResponse implementation is out of scope. So is an application that never feeds request data into those SVG positions. Rendering a static social card with fixed text is not the condition Vercel describes.

What is confirmed

NVD’s CVSS 4.0 score is 5.3 Medium. The vector is CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N. Vulnerable system confidentiality, integrity, and availability are none. The high scores are on the subsequent system, and the vector requires a user plus an extra attack condition. That is the only numeric score NVD publishes.

The GitHub Advisory API for GHSA-vcvr-r3jv-pc5j returns severity critical and no CVSS score. ThreatWire keeps the severity at critical because that is Vercel’s label for the Next.js impact, and it shows 5.3 as the published number.

Next.js 16.3.6 shipped on 22 September 2026. Satori 0.33.5 is the library fix. A public proof-of-concept repository, EQSTLab/CVE-2026-94545, followed on 29 September. The status is PoC Available. The fix existed before that repository, so this is not a 0-day. CISA has not listed it.

What is not confirmed

A figure of 9.5 has circulated with the CVE. It is not the NVD score. The advisory API still has no numeric score to replace 5.3. Other databases have printed their own CVSS 3.1 numbers. Those are not copied onto the record.

The advisory is also not a statement that every Next.js 16 application is remotely exploitable. The Edge runtime and applications that do not pass attacker-controlled SVG values are explicitly out of scope.

What to do

Applications in the Node.js ImageResponse range should move to Next.js 16.3.6 or later. Projects that depend on Satori directly should move to 0.33.5 or later. Until that upgrade, do not pass attacker-controlled values into SVG content, attributes, or styles. The sample request in the advisory, and the input used by the public repository, are not reprinted here.

Sources: NVD and the CVE record for CVE-2026-94545, Vercel advisory GHSA-vcvr-r3jv-pc5j, the Next.js 16.3.6 release, and the public repository linked from the CVE record.

Related CVEs

  • CVE-2026-94545 — Satori SVG injection affecting Next.js ImageResponse

Sources

Share on X@threatwire_https://www.threatwire.tech/research/reading-the-nextjs-imageresponse-advisory