Critical Next.js Vulnerability Enables Remote Code Execution via SVG Injection
A severe security flaw in Next.js (tracked as GHSA-vcvr-r3jv-pc5j) allows unauthenticated remote attackers to execute arbitrary code on affected servers by exploiting improperly escaped SVG content in dynamic image generation. The vulnerability impacts the Node.js implementation of ImageResponse in the next/og package, which is commonly used to generate Open Graph images, social media previews, and server-rendered graphics.
Affected Versions & Scope
The issue affects Next.js versions 16.2.0 through 16.3.5, with patches released in 16.3.6. The 15.x release line received a security-hardening update in 15.5.26. The underlying Satori library, which converts JSX to SVG, was also patched in version 0.33.5.
Exploitation Mechanism
The flaw arises when attacker-controlled input such as query parameters, API values, or form fields is embedded in SVG content, attributes, or styles processed by ImageResponse. If the input is not properly sanitized, malicious SVG markup can be interpreted as executable code, leading to remote code execution (RCE).
A vulnerable implementation might look like this:
import { ImageResponse } from 'next/og'
export async function GET(request: Request) {
const value = new URL(request.url).searchParams.get('value') ?? ''
return new ImageResponse(
<svg width="1200" height="630">
<title>{value}</title>
</svg>
)
}
An attacker could craft a malicious value parameter to trigger the exploit if the endpoint is exposed to the internet.
Conditions for Exploitation
Not all Next.js applications using ImageResponse are vulnerable. The flaw applies only if:
- The application runs Next.js 16.2.0–16.3.5.
- The
next/ogimage generation uses the Node.js implementation (EdgeImageResponseis unaffected). - Untrusted input is passed into SVG content, attributes, or CSS styles.
- The image-generation endpoint is publicly accessible.
Mitigation & Response
Vercel has released patched versions (16.3.6 and 15.5.26), and organizations are urged to upgrade immediately. If patching is not feasible, developers should ensure no untrusted input reaches SVG rendering. The Satori advisory warns that no complete workaround exists beyond upgrading and avoiding attacker-controlled content.
Given the potential for unauthenticated RCE, exposed next/og endpoints should be treated as a high-priority patching target.
Source: https://gbhackers.com/next-js-imageresponse-vulnerability/
Vercel TPRM report: https://www.rankiteo.com/company/vercel
"id": "ver1790864791",
"linkid": "vercel",
"type": "Vulnerability",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Users of Next.js versions '
'16.2.0–16.3.5 and 15.x '
'(unpatched)',
'industry': 'Technology/Web Development',
'location': 'Global',
'name': 'Next.js (Vercel)',
'size': 'Large (widely adopted)',
'type': 'Software Framework'}],
'attack_vector': 'SVG Injection via untrusted input in `ImageResponse`',
'customer_advisories': 'Users advised to upgrade immediately and review '
'`ImageResponse` implementations',
'description': 'A severe security flaw in Next.js (tracked as '
'GHSA-vcvr-r3jv-pc5j) allows unauthenticated remote attackers '
'to execute arbitrary code on affected servers by exploiting '
'improperly escaped SVG content in dynamic image generation. '
'The vulnerability impacts the Node.js implementation of '
'`ImageResponse` in the `next/og` package, which is commonly '
'used to generate Open Graph images, social media previews, '
'and server-rendered graphics.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'security vulnerability',
'operational_impact': 'Potential unauthorized code execution on '
'affected servers',
'systems_affected': 'Next.js applications using `ImageResponse` '
'with untrusted input'},
'lessons_learned': 'Importance of input sanitization in dynamic image '
'generation and prompt patching of critical '
'vulnerabilities',
'post_incident_analysis': {'corrective_actions': 'Patch release and input '
'sanitization guidance',
'root_causes': 'Improper escaping of SVG content '
'in `ImageResponse` leading to code '
'injection'},
'recommendations': ['Upgrade Next.js to patched versions (16.3.6 or 15.5.26)',
'Avoid passing untrusted input into SVG content, '
'attributes, or styles in `ImageResponse`',
'Restrict access to `next/og` endpoints if not required '
'publicly',
'Monitor for exploitation attempts on exposed endpoints'],
'references': [{'source': 'Vercel Security Advisory'},
{'source': 'GitHub Advisory (GHSA-vcvr-r3jv-pc5j)'},
{'source': 'Satori Library Advisory'}],
'response': {'communication_strategy': 'Public advisory and patch release by '
'Vercel',
'containment_measures': 'Upgrade to patched versions (16.3.6 or '
'15.5.26)',
'remediation_measures': 'Avoid passing untrusted input into SVG '
'rendering; apply security patches'},
'stakeholder_advisories': 'Vercel released public advisories and patches for '
'affected versions',
'title': 'Critical Next.js Vulnerability Enables Remote Code Execution via '
'SVG Injection',
'type': 'Remote Code Execution (RCE)',
'vulnerability_exploited': 'Improperly escaped SVG content in Next.js '
'`next/og` package (GHSA-vcvr-r3jv-pc5j)'}