Next.js 16.3.6 Patches Critical next/og RCE
On September 22, 2026 Vercel shipped 16.3.6 and 15.5.26 out of band to fix
CVE-2026-94545,
a Critical remote code execution flaw in ImageResponse from next/og. The
Next.js advisory scores it 9.5. If you generate Open Graph images on the
Node.js runtime and any part of that image is built from user input, upgrade
today.
The affected range is Next.js 16.2.0 through 16.3.5. Next.js 15 is not
affected by the RCE — 15.5.26 ships additional hardening for
next/og rather than a
fix for an exploitable path.
What actually triggers it
This is not a "you run Next.js, you are exploitable" bug. The advisory is precise about the condition: you are at risk if your application passes attacker-controlled values into SVG content, attributes, or styles during image generation.
The shape to look for is an OG route that interpolates something off the request
straight into the tree it hands to ImageResponse:
export async function GET(request: Request) {
const title = new URL(request.url).searchParams.get('title')
return new ImageResponse(<div>{title}</div>)
}
A title that a stranger controls is the whole prerequisite. That requirement is
visible in the CVSS v4 vector itself —
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H — where AT:P
marks an attack requirement that has to be present. Network reachable, no
privileges, no user interaction, but your code has to feed it.
Why the runtime matters
Only the Node.js implementation is affected; Edge-based ImageResponse is not.
The reason is in how next/og resolves its implementation. In
packages/next/src/server/og/image-response.ts at the v16.3.6 tag, the class is
a thin wrapper that dynamically picks one of two prebuilt bundles:
import(
process.env.NEXT_RUNTIME === 'edge'
? 'next/dist/compiled/@vercel/og/index.edge.js'
: 'next/dist/compiled/@vercel/og/index.node.js'
)
Two separate vendored builds, two different rasterization paths — and only the
Node one carries the vulnerable combination. This also explains why you will not
find satori in the Next.js package.json: it is compiled into
next/dist/compiled/@vercel/og, so an npm ls satori against your project tells
you nothing useful. The fix landed as a commit titled "Harden next/og SVG
serialization", not as a dependency bump you could audit for.
One CVE, two very different scores
The interesting part of this release is that CVE-2026-94545 was published twice, against two packages, with scores four points apart.
The upstream advisory is
GHSA-wx4j-mvgx-mqwp
against satori, the library that turns JSX into SVG. It is rated Moderate,
CVSS 5.3, affects >= 0.0.27 < 0.33.5, and is patched in 0.33.5. Its
description is deliberately narrow:
Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup.
On its own, that is markup injection. A value escapes its context and becomes
SVG structure instead of SVG text. The upstream advisory is explicit that "the
impact depends on how the generated SVG is consumed" — and in next/og's Node
path, it is consumed by further upstream rendering machinery where injected
markup escalates from cosmetic to code execution. Same defect, Moderate in
isolation, Critical in context.
That is worth internalising beyond this one CVE: a dependency's own severity rating describes the dependency, not your application. The escalation lives at the boundary. It is the same category of problem as the AVIF decoder path behind August's two Critical RCEs — an image pipeline where untrusted bytes reach native code.
What to do
Upgrade:
npm install next@16.3.6
If you cannot deploy immediately, the advisory's stopgap is to stop passing
untrusted user input into SVG content, attributes, or styles in the Node.js
ImageResponse. Hardcoded or fully server-derived OG images are not exploitable.
Moving an OG route to the Edge runtime also sidesteps it, though that is a
deployment change, not a patch.
If you use satori directly — plenty of teams do, outside Next.js entirely —
upgrade it to 0.33.5. There is no complete workaround short of upgrading, and
the upstream guidance is not to render attacker-controlled content until you have.
Credit for the finding goes to RaghavMaheshwari124 and rafabd1.
There is more coming on September 30
Do not treat 16.3.6 as this month's last patch. Vercel has pre-announced a scheduled security release for September 30, 2026, publishing 16.3.7 and 15.5.27 and covering nine advisories. Full impact details and affected ranges arrive with the release itself. Plan a second upgrade window next week rather than discovering it on the day.
Not sure whether your OG routes interpolate untrusted input, or which of your Next.js deployments are on the Node runtime versus Edge? Get in touch — auditing and patching Next.js applications is what we do.