Vercel: Next.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content

Vercel: Next.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content

Critical Next.js Vulnerability Enables Remote Code Execution via SVG Injection

A severe security flaw in Next.js (tracked as GHSA-vcvr-r3jv-pc5j) allows unauthenticated remote attackers to execute arbitrary code on affected servers by exploiting improperly escaped SVG content in dynamic image generation. The vulnerability impacts the Node.js implementation of ImageResponse in the next/og package, which is commonly used to generate Open Graph images, social media previews, and server-rendered graphics.

Affected Versions & Scope

The issue affects Next.js versions 16.2.0 through 16.3.5, with patches released in 16.3.6. The 15.x release line received a security-hardening update in 15.5.26. The underlying Satori library, which converts JSX to SVG, was also patched in version 0.33.5.

Exploitation Mechanism

The flaw arises when attacker-controlled input such as query parameters, API values, or form fields is embedded in SVG content, attributes, or styles processed by ImageResponse. If the input is not properly sanitized, malicious SVG markup can be interpreted as executable code, leading to remote code execution (RCE).

A vulnerable implementation might look like this:

import { ImageResponse } from 'next/og'
export async function GET(request: Request) {
  const value = new URL(request.url).searchParams.get('value') ?? ''
  return new ImageResponse(
    <svg width="1200" height="630">
      <title>{value}</title>
    </svg>
  )
}

An attacker could craft a malicious value parameter to trigger the exploit if the endpoint is exposed to the internet.

Conditions for Exploitation

Not all Next.js applications using ImageResponse are vulnerable. The flaw applies only if:

  • The application runs Next.js 16.2.0–16.3.5.
  • The next/og image generation uses the Node.js implementation (Edge ImageResponse is unaffected).
  • Untrusted input is passed into SVG content, attributes, or CSS styles.
  • The image-generation endpoint is publicly accessible.

Mitigation & Response

Vercel has released patched versions (16.3.6 and 15.5.26), and organizations are urged to upgrade immediately. If patching is not feasible, developers should ensure no untrusted input reaches SVG rendering. The Satori advisory warns that no complete workaround exists beyond upgrading and avoiding attacker-controlled content.

Given the potential for unauthenticated RCE, exposed next/og endpoints should be treated as a high-priority patching target.

Source: https://gbhackers.com/next-js-imageresponse-vulnerability/

Vercel TPRM report: https://www.rankiteo.com/company/vercel

"id": "ver1790864791",
"linkid": "vercel",
"type": "Vulnerability",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Users of Next.js versions '
                                              '16.2.0–16.3.5 and 15.x '
                                              '(unpatched)',
                        'industry': 'Technology/Web Development',
                        'location': 'Global',
                        'name': 'Next.js (Vercel)',
                        'size': 'Large (widely adopted)',
                        'type': 'Software Framework'}],
 'attack_vector': 'SVG Injection via untrusted input in `ImageResponse`',
 'customer_advisories': 'Users advised to upgrade immediately and review '
                        '`ImageResponse` implementations',
 'description': 'A severe security flaw in Next.js (tracked as '
                'GHSA-vcvr-r3jv-pc5j) allows unauthenticated remote attackers '
                'to execute arbitrary code on affected servers by exploiting '
                'improperly escaped SVG content in dynamic image generation. '
                'The vulnerability impacts the Node.js implementation of '
                '`ImageResponse` in the `next/og` package, which is commonly '
                'used to generate Open Graph images, social media previews, '
                'and server-rendered graphics.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'security vulnerability',
            'operational_impact': 'Potential unauthorized code execution on '
                                  'affected servers',
            'systems_affected': 'Next.js applications using `ImageResponse` '
                                'with untrusted input'},
 'lessons_learned': 'Importance of input sanitization in dynamic image '
                    'generation and prompt patching of critical '
                    'vulnerabilities',
 'post_incident_analysis': {'corrective_actions': 'Patch release and input '
                                                  'sanitization guidance',
                            'root_causes': 'Improper escaping of SVG content '
                                           'in `ImageResponse` leading to code '
                                           'injection'},
 'recommendations': ['Upgrade Next.js to patched versions (16.3.6 or 15.5.26)',
                     'Avoid passing untrusted input into SVG content, '
                     'attributes, or styles in `ImageResponse`',
                     'Restrict access to `next/og` endpoints if not required '
                     'publicly',
                     'Monitor for exploitation attempts on exposed endpoints'],
 'references': [{'source': 'Vercel Security Advisory'},
                {'source': 'GitHub Advisory (GHSA-vcvr-r3jv-pc5j)'},
                {'source': 'Satori Library Advisory'}],
 'response': {'communication_strategy': 'Public advisory and patch release by '
                                        'Vercel',
              'containment_measures': 'Upgrade to patched versions (16.3.6 or '
                                      '15.5.26)',
              'remediation_measures': 'Avoid passing untrusted input into SVG '
                                      'rendering; apply security patches'},
 'stakeholder_advisories': 'Vercel released public advisories and patches for '
                           'affected versions',
 'title': 'Critical Next.js Vulnerability Enables Remote Code Execution via '
          'SVG Injection',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'Improperly escaped SVG content in Next.js '
                            '`next/og` package (GHSA-vcvr-r3jv-pc5j)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.