chiprook
← Security
SecuritySeptember 23, 2026, 14:04

Critical Next.js ImageResponse flaw allows server code execution

Vercel disclosed a vulnerability in Next.js that lets attackers execute code on the server via ImageResponse, the feature that generates Open Graph and social preview images. The risk applies when an app feeds attacker-controlled values, such as text from the request URL, into the image. A fix shipped on September 22.

Critical Next.js ImageResponse flaw allows server code execution
#Next.js#Vercel
Read next
Security

Okta bets on identity to control AI agents with new platform

Security

Ryuk ransomware member sentenced to 24 months in prison

Security

AI Agents Become a New Malware Distribution Channel

Security

Expert warns shadow AI and autonomous agents bypass security