Reading the Next.js ImageResponse advisory
CVE-2026-94545 is a Satori escaping bug that Vercel says can become code execution in Node.js next/og. The only published numeric score is 5.3. Next.js 16.3.6 is the fix. A public PoC exists.
Published 5 Oct 2026 · Updated 5 Oct 2026
What happened
CVE-2026-94545 starts in Satori, the library that turns HTML and CSS into SVG. From 0.0.27 up to, but not including, 0.33.5, some values are written into the generated SVG without proper escaping. Crafted values can be read as markup. CWE-116 is the weakness NVD records. The CVE text says the damage depends on whatever consumes that SVG.
Next.js sits on that path when an application uses the Node.js ImageResponse from next/og. Vercel advisory GHSA-vcvr-r3jv-pc5j, published 22 September 2026, says that case can become remote code execution. The Next.js range is 16.2.0 through every version before 16.3.6.
Who is affected
Two products share the CVE record, and they are not the same deployment. A direct dependency on Satori in the vulnerable range is the library bug. A Next.js application is in the Vercel advisory only when it is on 16.2.0 or newer, older than 16.3.6, and it passes attacker-controlled values into SVG content, attributes, or styles while generating an image.
The Edge ImageResponse implementation is out of scope. So is an application that never feeds request data into those SVG positions. Rendering a static social card with fixed text is not the condition Vercel describes.
What is confirmed
NVD’s CVSS 4.0 score is 5.3 Medium. The vector is CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N. Vulnerable system confidentiality, integrity, and availability are none. The high scores are on the subsequent system, and the vector requires a user plus an extra attack condition. That is the only numeric score NVD publishes.
The GitHub Advisory API for GHSA-vcvr-r3jv-pc5j returns severity critical and no CVSS score. ThreatWire keeps the severity at critical because that is Vercel’s label for the Next.js impact, and it shows 5.3 as the published number.
Next.js 16.3.6 shipped on 22 September 2026. Satori 0.33.5 is the library fix. A public proof-of-concept repository, EQSTLab/CVE-2026-94545, followed on 29 September. The status is PoC Available. The fix existed before that repository, so this is not a 0-day. CISA has not listed it.
What is not confirmed
A figure of 9.5 has circulated with the CVE. It is not the NVD score. The advisory API still has no numeric score to replace 5.3. Other databases have printed their own CVSS 3.1 numbers. Those are not copied onto the record.
The advisory is also not a statement that every Next.js 16 application is remotely exploitable. The Edge runtime and applications that do not pass attacker-controlled SVG values are explicitly out of scope.
What to do
Applications in the Node.js ImageResponse range should move to Next.js 16.3.6 or later. Projects that depend on Satori directly should move to 0.33.5 or later. Until that upgrade, do not pass attacker-controlled values into SVG content, attributes, or styles. The sample request in the advisory, and the input used by the public repository, are not reprinted here.
Sources: NVD and the CVE record for CVE-2026-94545, Vercel advisory GHSA-vcvr-r3jv-pc5j, the Next.js 16.3.6 release, and the public repository linked from the CVE record.
Related CVEs
- CVE-2026-94545 — Satori SVG injection affecting Next.js ImageResponse