Vulnerability GHSA-vcvr-r3jv-pc5j

Critical
CRITICAL RISK
CVSS Score: 9.5
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
2 hours ago
September 30, 2026 at 02:48 PM UTC
Next.js: Remote Code Execution in next/og ImageResponse
16.2.0 - 16.3.5
16.2.0 - 16.3.5

Summary

Next.js: Remote Code Execution in next/og ImageResponse

Details

Impact

The Node.js ImageResponse implementation from next/og is affected by an upstream vulnerability. This can lead to remote code execution.

Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation:

import { ImageResponse } from 'next/og'

export async function GET(request: Request) {
  const value = new URL(request.url).searchParams.get('value') ?? ''

  return new ImageResponse(
    <svg width="1200" height="630">
      <title>{value}</title>
    </svg>
  )
}

Applications using the Edge ImageResponse implementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected.

Workaround

If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js ImageResponse implementation from next/og.

Impacted packages

Timeline

Published
2 hours ago
September 30, 2026 at 02:48 PM UTC
Fixed (16.3.6)
Unknown
Unknown
Last Modified
2 hours ago
September 30, 2026 at 03:00 PM UTC