Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Next.js Vulnerability Allows Server Code Execution via SVG

Next.js Vulnerability Allows Server Code Execution via SVG

Posted on September 23, 2026 By CWS

A significant security flaw has been identified in Next.js, a popular web development framework, which could enable attackers to execute code on servers. This vulnerability is linked to the ImageResponse feature, responsible for generating Open Graph and social media preview images, according to Vercel, the company behind Next.js.

Understanding the Vulnerability

The flaw, cataloged as CVE-2026-94545, affects versions 16.2.0 to 16.3.5 of Next.js when ImageResponse operates on the Node.js runtime. Vercel has classified this issue as critical, assigning it a CVSS score of 9.5. Notably, the Edge version of ImageResponse and version 15 of Next.js are not impacted.

The vulnerability arises when applications incorporate attacker-controlled data into SVG content during image generation. The advisory warns about the risk of inserting such values into SVG elements, which could lead to unintended code execution.

Identifying and Mitigating the Risk

To identify if an application uses the vulnerable feature, developers should look for ImageResponse imports from next/og, particularly in route handlers or opengraph-image files. The vulnerability can be mitigated by updating to Next.js version 16.3.6, released on September 22, which addresses the flaw. For those unable to upgrade immediately, it is crucial to prevent attacker-controlled values from entering SVG content.

As of September 23, no known exploits or attacks leveraging this vulnerability have been reported. Additionally, there is no public exploit code available, and the issue has not yet been listed in the GitHub Advisory Database.

Future Implications and Recommendations

The underlying issue originates from Satori, a library used by Next.js to convert image layouts to SVG before generating PNGs. Satori’s advisory, which rates the issue as moderate with a CVSS score of 5.3, emphasizes the need for developers using Satori directly to update to version 0.33.5.

This vulnerability highlights the importance of regular updates and security checks in web applications to protect against potential exploits. Developers are advised to remain vigilant and ensure their systems are patched promptly to prevent any unauthorized code execution.

Vercel’s response to previous flaws suggests that hosted applications may receive automatic protections, though no such assurances have been provided for this specific flaw. As a precaution, developers should verify their Next.js version and review any potential vulnerabilities that might affect their applications.

The Hacker News Tags:code execution, CVE-2026-94545, ImageResponse, Next.js, Node.js, Satori, SVG, Vercel, Vulnerability, web security

Post navigation

Previous Post: Check Point Issues Critical Patch for Zero-Day Vulnerability
Next Post: F5 BIG-IP Zero-Day Vulnerability Exploited

Related Posts

Hackers Turn Velociraptor DFIR Tool Into Weapon in LockBit Ransomware Attacks Hackers Turn Velociraptor DFIR Tool Into Weapon in LockBit Ransomware Attacks The Hacker News
APT Campaigns, Browser Hijacks, AI Malware, Cloud Breaches and Critical CVEs APT Campaigns, Browser Hijacks, AI Malware, Cloud Breaches and Critical CVEs The Hacker News
Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices The Hacker News
Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid The Hacker News
5 Lessons from River Island 5 Lessons from River Island The Hacker News
ClickFix Campaigns Enhance Malware Tactics with New Loaders ClickFix Campaigns Enhance Malware Tactics with New Loaders The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Leading Decentralized Identity Solutions for 2026
  • Arista Releases Urgent Patch for Critical VCO Vulnerability
  • Critical F5 BIG-IP APM Flaw Exploited for RCE
  • F5 BIG-IP Zero-Day Vulnerability Exploited
  • Next.js Vulnerability Allows Server Code Execution via SVG

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Leading Decentralized Identity Solutions for 2026
  • Arista Releases Urgent Patch for Critical VCO Vulnerability
  • Critical F5 BIG-IP APM Flaw Exploited for RCE
  • F5 BIG-IP Zero-Day Vulnerability Exploited
  • Next.js Vulnerability Allows Server Code Execution via SVG

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark