Node.js ImageResponse Implementation Vulnerability Enables Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A critical vulnerability in Next.js could allow remote code execution in applications that use the Node.js implementation of ImageResponse from the next/og package. The issue, tracked as GHSA-vcvr-r3jv-pc5j, affects Next.js versions 16.2.0 through 16.3.5 and has been fixed in version 16.3.6.

The flaw exists when an application passes attacker-controlled input into SVG content, SVG attributes, or style properties during dynamic image generation.

Developers commonly use ImageResponse to create Open Graph images, social-media preview images, and other graphics generated at request time.

A vulnerable application may read a value from a URL parameter and include it in an SVG element. For example, an endpoint could receive a value parameter from a remote visitor and place it inside an SVG <title> tag.

If the value is not safely handled, a specially crafted payload may reach the underlying image-rendering process and lead to remote code execution.

Node.js ImageResponse Vulnerability

The GitHub advisory (GHSA-vcvr-r3jv-pc5j ) states that the risk is limited to the Node.js implementation of next/og ImageResponse. Applications using the Edge ImageResponse implementation are not affected. Likewise, an application is not exposed if it does not insert untrusted input into SVG markup, attributes, or styles.

The vulnerability stems from an upstream issue in Satori, the SVG generation library used in the rendering chain. Satori improperly escaped certain values before placing them into generated SVG output, allowing crafted data to be interpreted as SVG markup.

The upstream Satori flaw, identified as CVE-2026-94545 and GHSA-wx4j-mvgx-mqwp, affects versions from 0.0.27 through 0.33.4 and was patched in version 0.33.5.

GitHub rated the Next.js issue as critical under CVSS v4; the advisory lists network-based exploitation, low attack complexity, no required privileges, and no user interaction. Successful exploitation could affect confidentiality, integrity, and availability of both the vulnerable system and downstream systems.

Attackers could target public image-generation routes that process query-string values, post content, profile names, page titles, or other user-supplied data.

Because Open Graph image endpoints are frequently internet-facing, developers should review every ImageResponse route that accepts external input.

The affected package is next on npm. Versions 16.2.0 through 16.3.5 are vulnerable, while version 16.3.6 contains the security fix. GitHub has classified the issue under CWE-1395, which covers dependencies on vulnerable third-party components.

Organizations should upgrade Next.js to version 16.3.6 as soon as possible. The update incorporates the required fix for the vulnerable rendering path.

Teams unable to upgrade immediately should ensure that no attacker-controlled data reaches SVG content, attributes, or CSS styles generated through the Node.js ImageResponse implementation.

Input validation alone may not be sufficient if untrusted strings can still be interpreted as markup. Developers should also audit custom image-generation endpoints, especially routes that use values from requests.

URL, URL search parameters, headers, form submissions, CMS content, or user profiles.URL, URL search parameters, headers, form submissions, CMS content, or user profiles.

Switching affected routes to the Edge ImageResponse implementation may reduce exposure. However, organizations should test rendering behavior and deployment compatibility before making architectural changes.

The advisory credits security researchers RaghavMaheshwari124 and rafabd1 for reporting the issue. Given the potential for unauthenticated remote code execution, affected Next.js deployments should treat the update as an urgent patching priority.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Node.js ImageResponse Implementation Vulnerability Enables Remote Code Execution appeared first on Cyber Security News.