CVE-2026-94545: RCE in Next.js via next/og and Satori
A remote code execution flaw CVE-2026-94545 was found in the Next.js next/og route: Satori fails to escape user text in generated SVG, and the native libvips/libxml2 parser corrupts memory. It is fixed in Next.js 16.3.6 and Satori 0.33.5; Next.js 16.2.0–16.3.5 on Node.js with sharp are affected.
- Satori 0.0.27–0.33.4 fails to escape text embedded in SVG
- Affected: Next.js 16.2.0–16.3.5 on Node.js with sharp installed
- The non-PIE official Node build removes the need for an address leak
- ZoomEye: 1,733,654 assets for app="Next.js", no CVE-indexed exposure
Read next
Security