Next.js 16 ImageResponse RCE: Patch to 16.3.6 Now

Yatish Goel

Yatish Goel

Co-Founder & CTO

A forest green image frame with a repaired shield-shaped corner on a cream background

Next.js published an out-of-band security update on September 22, 2026 for a critical next/og flaw. The affected range is Next.js 16.2.0 through 16.3.5, and the patched release is 16.3.6. GitHub gives CVE-2026-94545 a 9.5 out of 10 CVSS v4 score.

You should patch even though not every Next.js app is exploitable. The vulnerable path needs three things at once: an affected Next.js version, the Node.js ImageResponse implementation, and attacker-controlled data passed into SVG content, attributes, or styles. Check those conditions first, then upgrade, rebuild, redeploy, and verify the version running in production.

Next.js ImageResponse RCE is CVE-2026-94545, a remote code execution path in the Node.js implementation of ImageResponse from next/og. It affects Next.js versions at or above 16.2.0 and below 16.3.6 when untrusted values reach generated SVG markup.

Is your Next.js ImageResponse route affected?

Do not stop at the version in package.json. A range such as ^16.2.0 can resolve differently across lockfiles and environments. Check the installed dependency in the exact build context used for production:

Terminal
npm ls next
npm ls satori

Then search the application for imports and file conventions that create social images:

Terminal
rg "ImageResponse|next/og" app src pages
rg "opengraph-image|twitter-image" app src pages

The Next.js advisory says exploitation requires attacker-controlled values in SVG content, attributes, or styles during image generation. Query parameters, route parameters, database fields, user profiles, uploaded metadata, and remote API responses all deserve tracing if they reach ImageResponse.

CheckIn the affected scopeOutside the stated scope
Next.js version`>=16.2.0 <16.3.6``16.3.6` or later
Image runtimeNode.js `ImageResponse`Edge `ImageResponse`
Data flowAttacker-controlled value reaches SVG content, attributes, or stylesNo attacker-controlled value reaches those SVG fields
Next.js 15Not affected by this RCE; 15.5.26 adds hardeningNot a reason to ignore its October 21, 2026 end of life

Table: Scope stated by the Next.js security update and GitHub advisory.

Attacker-controlled input is any value an outside user can influence before it reaches generated SVG, even if that value came through your database or another API rather than directly from the current request.

The distinction matters because generated Open Graph images often combine trusted layout code with untrusted names, titles, search terms, or filenames. The route can look static while one text node or style value still comes from a request.

How to patch the Next.js ImageResponse RCE

The official security update gives the direct fix for the affected major line:

Terminal
npm install next@16.3.6
npm ls next
npm run build

Commit the package manifest and lockfile together. If your deployment installs with a frozen lockfile, changing only package.json may leave the build broken or preserve an older resolved package. If you build a container, create a new image rather than restarting an old one.

Next, deploy the new artifact. The Next.js deployment documentation separates the build and start stages for a Node.js server, so a local dependency update does not alter an existing production process. Static exports have limited feature support and do not run server-only image generation, but verify the deployed architecture instead of assuming the project stayed static.

After deployment, request every affected Open Graph or social-image route with ordinary values and edge-case values already accepted by the product. Confirm that the route returns an image and that logs show no rendering error. Then inspect the production build or deployment metadata to establish that it contains Next.js 16.3.6 or later.

A complete patch changes the resolved dependency, produces a fresh build, replaces the running artifact, and verifies the deployed version. Editing a manifest completes only the first part.

What if you cannot deploy 16.3.6 today?

The Next.js advisory gives one temporary workaround: do not pass attacker-controlled values into SVG content, attributes, or styles rendered by Node.js ImageResponse. Replace those values with fixed content, remove the dynamic image route, or route image generation away from the Node.js implementation until the patched build is live.

Do not treat escaping code as a complete permanent fix. The related Satori advisory says no complete workaround exists besides upgrading. Satori versions from 0.0.27 up to, but not including, 0.33.5 are affected by improper escaping; 0.33.5 is patched.

The upstream issue is rated 5.3 out of 10, while its Next.js execution path is rated 9.5 out of 10. The difference is a useful warning: dependency severity cannot be read without the way your framework consumes its output.

How should you review the route after patching?

The patch closes the disclosed flaw. You should still reduce unnecessary input paths because dynamic image routes process data at request time.

  1. List every ImageResponse call and identify its runtime.
  2. Trace each value used inside SVG content, attributes, and styles back to its source.
  3. Record whether the source is fixed, authenticated, or open to anyone on the internet.
  4. Add tests for the input shapes the route intentionally supports.
  5. Verify generated images and deployment logs after the patched build goes live.

The ImageResponse reference says the API uses @vercel/og, Satori, and Resvg to convert HTML and CSS into PNG. It also documents a maximum bundle size of 500KB and default dimensions of 1200 by 630 pixels. Those are operational constraints, not protections against unsafe input.

If this review exposes old framework work beyond the image route, use the Next.js 15 end-of-life checklist to separate the security patch from the larger migration. HeyDev handles broader repairs and production automation through its automation service, but the urgent step here is narrower: get the affected deployment onto 16.3.6.

What we did not test

We did not reproduce CVE-2026-94545, run exploit code, or measure the effect of a particular hosting provider's firewall. We also did not test whether an application-specific sanitizer blocks every crafted value.

This article applies the scope and remediation published by Next.js and the two GitHub advisories. It does not claim that a version match proves exploitation, that an Edge route is vulnerable, or that removing one query parameter finds every attacker-controlled value.

Frequently asked questions

Is every Next.js 16 application vulnerable to CVE-2026-94545?
No. The Next.js advisory limits the affected range to 16.2.0 through 16.3.5 and requires the Node.js ImageResponse implementation to receive attacker-controlled values in SVG content, attributes, or styles. Edge ImageResponse routes and routes without attacker-controlled SVG values are outside the stated affected scope.
Does upgrading the package protect an already running deployment?
Not by itself. Changing package.json or the lockfile does not replace the code already serving traffic. Install Next.js 16.3.6, confirm the resolved version, run a production build, deploy that artifact, and verify the live environment now runs the patched dependency.
What can I do if I cannot upgrade Next.js immediately?
Remove attacker-controlled values from SVG content, attributes, and styles rendered by the Node.js ImageResponse implementation. That is the workaround in the Next.js advisory. Treat it as temporary: the related Satori advisory says no complete workaround exists besides upgrading, so schedule the patch rather than keeping the filter indefinitely.
Is Next.js 15 affected by this remote code execution issue?
Next.js says the 15.x line is not affected by this remote code execution issue. It still released 15.5.26 for related hardening. If the application remains on 15.x, install that maintenance release and keep the separate October 21, 2026 end-of-life deadline in view.

Sources

  1. Next.js Security Update for a Critical Upstream Issue
  2. Remote Code Execution in next/og ImageResponse
  3. Improper escaping in Satori-generated SVG
  4. Next.js ImageResponse reference

#Next.js 16 #ImageResponse #next/og #CVE-2026-94545 #Satori #security patch

Yatish Goel

Yatish Goel

Co-Founder & CTO

US Startup ExperienceIIT Kanpur

Full-stack architect with US startup experience and an IIT Kanpur degree. Yatish drives the technical vision at HeyDev, designing robust architectures and leading development across web, mobile, and AI projects.

Related articles