chiprook
← Security
SecurityOctober 10, 2026, 05:40

CVE-2026-94545: RCE in Next.js via next/og and Satori

A remote code execution flaw CVE-2026-94545 was found in the Next.js next/og route: Satori fails to escape user text in generated SVG, and the native libvips/libxml2 parser corrupts memory. It is fixed in Next.js 16.3.6 and Satori 0.33.5; Next.js 16.2.0–16.3.5 on Node.js with sharp are affected.

CVE-2026-94545: RCE in Next.js via next/og and Satori
#Next.js#Satori#Node.js#Sharp
Read next
Security

Satori and Next.js SVG escaping flaw led to RCE risk

Software

Next.js ships v16.3.6 and v15.5.26 with next/og security patches

Security

CVE-2026-29057: HTTP request smuggling via Next.js rewrites

Security

CVE-2026-78249: Path Traversal in Fujifilm and Sharp MFP Web Consoles