SB2026092349 - Input validation error in Next.js



SB2026092349 - Input validation error in Next.js

Published: September 23, 2026

Security Bulletin ID SB2026092349
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Input validation error (CVE-ID: CVE-2026-94545)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an upstream vulnerability in the Node.js ImageResponse implementation from next/og when generating images from SVG content, attributes, or styles containing attacker-controlled values. A remote attacker can supply crafted values for SVG content, attributes, or styles to execute arbitrary code.

Applications using the Edge ImageResponse implementation are not affected.


Remediation

Install update from vendor's website.