CVE-2026-94545: Critical SVG Injection in Vercel Satori and Next.js ImageResponse
A CWE-116 vulnerability rated CVSS 9.8 in Vercel Satori and Next.js ImageResponse lets unauthenticated attackers inject SVG markup into dynamic Open Graph images, enabling SSRF, local file read and RCE. Fixed in Next.js 16.3.6 and Satori 0.33.5.
- CVSS 9.8: markup injection via unescaped SVG parameters
- Affected: Next.js >= 16.2.0, < 16.3.6 and Satori >= 0.0.27, < 0.33.5
- Impact: SSRF, local file read and remote code execution
- Patches: Next.js 16.3.6 (or 15.5.26) and Satori 0.33.5
Read next
Security