chiprook
← Security
SecurityOctober 3, 2026, 03:26

Satori and Next.js SVG escaping flaw led to RCE risk

A flaw in Satori's escaping of values inserted into generated SVG let attacker-controlled data be parsed as markup. It affected the Node.js ImageResponse path in Next.js 16.2.0–16.3.6, potentially enabling remote code execution; fixes shipped in Satori 0.33.5 and Next.js 16.3.6.

Satori and Next.js SVG escaping flaw led to RCE risk
#Satori#Next.js
Read next
Security

CVE-2026-94545: Critical SVG Injection in Vercel Satori and Next.js ImageResponse

Security

Critical Next.js ImageResponse flaw allows server code execution

Security

Click2Shell: WordPress parser discrepancy led to RCE

Security

N-able N-central Pre-Auth RCE Highlights RMM Concentration Risk