SB2026092349 - Input validation error in Next.js
Published: September 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Input validation error (CVE-ID: CVE-2026-94545)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an upstream vulnerability in the Node.js ImageResponse implementation from next/og when generating images from SVG content, attributes, or styles containing attacker-controlled values. A remote attacker can supply crafted values for SVG content, attributes, or styles to execute arbitrary code.
Applications using the Edge ImageResponse implementation are not affected.
Remediation
Install update from vendor's website.