PT-2026-97045 · Vercel · Next.Js
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Next.js versions 16.2.0 through 16.3.5
Description
A flaw in the Node.js implementation of the
ImageResponse component within the next/og package occurs due to improper encoding or escaping of output data. This issue arises when attacker-controlled values are passed into SVG content, attributes, or styles during the dynamic generation of images, such as Open Graph social preview cards. An unauthenticated remote attacker can exploit this by injecting malicious markup into the generated SVG, which can lead to memory corruption in native image libraries (such as sharp, libvips, librsvg, and libxml2) and ultimately result in remote code execution on the server. The Edge runtime implementation and configurations that do not use the sharp library are not affected.Recommendations
Upgrade to Next.js version 16.3.6.
As a temporary workaround, remove all untrusted SVG input from the Node.js
ImageResponse implementation.Exploit
Fix
RCE
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Next.Js