chiprook
← Security
SecuritySeptember 30, 2026, 22:31

CVE-2026-94545: Critical SVG Injection in Vercel Satori and Next.js ImageResponse

A CWE-116 vulnerability rated CVSS 9.8 in Vercel Satori and Next.js ImageResponse lets unauthenticated attackers inject SVG markup into dynamic Open Graph images, enabling SSRF, local file read and RCE. Fixed in Next.js 16.3.6 and Satori 0.33.5.

CVE-2026-94545: Critical SVG Injection in Vercel Satori and Next.js ImageResponse
#Vercel#Next.js#Satori
Read next
Security

Critical Next.js ImageResponse flaw allows server code execution

Software

Next.js ships v16.3.6 and v15.5.26 with next/og security patches

Security

WatchGuard Patches Critical Fireware OS Code Injection Flaw

Security

Cisco Secure Email Gateway hit by critical CVE-2026-76443 injection flaw