PT-2026-105541 · Npm · Next
Published
2026-09-30
·
Updated
2026-09-30
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Impact
The Node.js
ImageResponse implementation from next/og is affected by an upstream vulnerability. This can lead to remote code execution.Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation:
tsx
import { ImageResponse } from 'next/og'
export async function GET(request: Request) {
const value = new URL(request.url).searchParams.get('value') ?? ''
return new ImageResponse(
<svg width="1200" height="630">
<title>{value}</title>
</svg>
)
}Applications using the Edge
ImageResponse implementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected.Workaround
If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js
ImageResponse implementation from next/og.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Next