Blog / 01

Next.js 16.3.6 Patches Critical next/og RCE

WebRestart

On September 22, 2026 Vercel shipped 16.3.6 and 15.5.26 out of band to fix CVE-2026-94545, a Critical remote code execution flaw in ImageResponse from next/og. The Next.js advisory scores it 9.5. If you generate Open Graph images on the Node.js runtime and any part of that image is built from user input, upgrade today.

The affected range is Next.js 16.2.0 through 16.3.5. Next.js 15 is not affected by the RCE — 15.5.26 ships additional hardening for next/og rather than a fix for an exploitable path.

What actually triggers it

This is not a "you run Next.js, you are exploitable" bug. The advisory is precise about the condition: you are at risk if your application passes attacker-controlled values into SVG content, attributes, or styles during image generation.

The shape to look for is an OG route that interpolates something off the request straight into the tree it hands to ImageResponse:

export async function GET(request: Request) {
  const title = new URL(request.url).searchParams.get('title')
  return new ImageResponse(<div>{title}</div>)
}

A title that a stranger controls is the whole prerequisite. That requirement is visible in the CVSS v4 vector itself — CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H — where AT:P marks an attack requirement that has to be present. Network reachable, no privileges, no user interaction, but your code has to feed it.

Why the runtime matters

Only the Node.js implementation is affected; Edge-based ImageResponse is not. The reason is in how next/og resolves its implementation. In packages/next/src/server/og/image-response.ts at the v16.3.6 tag, the class is a thin wrapper that dynamically picks one of two prebuilt bundles:

import(
  process.env.NEXT_RUNTIME === 'edge'
    ? 'next/dist/compiled/@vercel/og/index.edge.js'
    : 'next/dist/compiled/@vercel/og/index.node.js'
)

Two separate vendored builds, two different rasterization paths — and only the Node one carries the vulnerable combination. This also explains why you will not find satori in the Next.js package.json: it is compiled into next/dist/compiled/@vercel/og, so an npm ls satori against your project tells you nothing useful. The fix landed as a commit titled "Harden next/og SVG serialization", not as a dependency bump you could audit for.

One CVE, two very different scores

The interesting part of this release is that CVE-2026-94545 was published twice, against two packages, with scores four points apart.

The upstream advisory is GHSA-wx4j-mvgx-mqwp against satori, the library that turns JSX into SVG. It is rated Moderate, CVSS 5.3, affects >= 0.0.27 < 0.33.5, and is patched in 0.33.5. Its description is deliberately narrow:

Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup.

On its own, that is markup injection. A value escapes its context and becomes SVG structure instead of SVG text. The upstream advisory is explicit that "the impact depends on how the generated SVG is consumed" — and in next/og's Node path, it is consumed by further upstream rendering machinery where injected markup escalates from cosmetic to code execution. Same defect, Moderate in isolation, Critical in context.

That is worth internalising beyond this one CVE: a dependency's own severity rating describes the dependency, not your application. The escalation lives at the boundary. It is the same category of problem as the AVIF decoder path behind August's two Critical RCEs — an image pipeline where untrusted bytes reach native code.

What to do

Upgrade:

npm install next@16.3.6

If you cannot deploy immediately, the advisory's stopgap is to stop passing untrusted user input into SVG content, attributes, or styles in the Node.js ImageResponse. Hardcoded or fully server-derived OG images are not exploitable. Moving an OG route to the Edge runtime also sidesteps it, though that is a deployment change, not a patch.

If you use satori directly — plenty of teams do, outside Next.js entirely — upgrade it to 0.33.5. There is no complete workaround short of upgrading, and the upstream guidance is not to render attacker-controlled content until you have.

Credit for the finding goes to RaghavMaheshwari124 and rafabd1.

There is more coming on September 30

Do not treat 16.3.6 as this month's last patch. Vercel has pre-announced a scheduled security release for September 30, 2026, publishing 16.3.7 and 15.5.27 and covering nine advisories. Full impact details and affected ranges arrive with the release itself. Plan a second upgrade window next week rather than discovering it on the day.


Not sure whether your OG routes interpolate untrusted input, or which of your Next.js deployments are on the Node runtime versus Edge? Get in touch — auditing and patching Next.js applications is what we do.