Input validation error in Next.js - CVE-2026-94545
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an upstream vulnerability in the Node.js ImageResponse implementation from next/og when generating images from SVG content, attributes, or styles containing attacker-controlled values. A remote attacker can supply crafted values for SVG content, attributes, or styles to execute arbitrary code.
Applications using the Edge ImageResponse implementation are not affected.