Critical
research
Reading the Next.js ImageResponse advisory
CVE-2026-94545 is a Satori escaping bug that Vercel says can become code execution in Node.js next/og. The only published numeric score is 5.3. Next.js 16.3.6 is the fix. A public PoC exists.
Published 3h ago