PT-2026-105541 · Npm · Next

Publicado

2026-09-30

·

Atualizado

2026-09-30

CVSS v4.0

9.5

Crítica

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Impact

The Node.js ImageResponse implementation from next/og is affected by an upstream vulnerability. This can lead to remote code execution.
Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation:
tsx
import { ImageResponse } from 'next/og'

export async function GET(request: Request) {
 const value = new URL(request.url).searchParams.get('value') ?? ''

 return new ImageResponse(
  <svg width="1200" height="630">
   <title>{value}</title>
  </svg>
 )
}
Applications using the Edge ImageResponse implementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected.

Workaround

If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js ImageResponse implementation from next/og.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-VCVR-R3JV-PC5J

Produtos afetados

Next