Next.js Patches Its Third Critical RCE in Two Months — This Time the OG Image Generator Was the Attack Surface

The third critical bug in two months landed in Next.js on Tuesday, and for the second month running it was hiding in the image pipeline. Not in the router, not in the cache, not in the auth middleware. In the bit of the framework that turns your post title into a pretty square for social media.

That’s an odd place for an attack surface to live, and it’s worth understanding why it’s there.

What actually shipped

On 22 September 2026, Vercel pushed an out-of-band security release: Next.js 16.3.6 (Active LTS) and 15.5.26 (Maintenance LTS). The headline advisory is GHSA-vcvr-r3jv-pc5j, tracked as CVE-2026-94545 — a critical-severity remote code execution in the Node.js ImageResponse implementation in next/og.

The affected range is Next.js 16.2.0 through 16.3.5. The Edge runtime’s ImageResponse is not affected, and the 15.x line isn’t hit by the RCE at all — 15.5.26 ships related hardening only. If you’re on the Edge implementation, or you’re on 15.x and you’re not feeding untrusted input into ImageResponse, the official position is that you’re not expected to be affected.

The fix is a dependency upgrade, and that’s the detail that makes this interesting.

The boring library that carried the exploit

The root cause is upstream. Next.js’s own advisory says that “under specific conditions, improper escaping in SVG output generated by Satori could lead to remote code execution due to vulnerabilities in other upstream dependencies.” Satori is the little library that turns your JSX-ish description into an SVG, which then gets rasterised into the PNG that becomes your Open Graph card.

Satori published its own advisory the same day — GHSA-wx4j-mvgx-mqwp, “Improper escaping in Satori-generated SVG.” On its own it’s rated Moderate, CVSS 5.3. Affected: satori 0.0.27 through 0.33.4, patched in 0.33.5.

So the chain reads: crafted input flows into Satori, Satori doesn’t escape it properly, the resulting SVG is interpreted as markup, and somewhere downstream of that the escaping failure becomes a code-execution path. A “moderate” library-level bug, in isolation, becomes a “critical” RCE once it’s embedded in a framework that renders untrusted content by design. That’s the classic supply-chain shape: the most dangerous code is the unglamorous dependency nobody audits, not the framework on the poster.

Why the image pipeline keeps getting picked

This is the second month in a row that Next.js’s criticals have come from image handling. In the 25 August release (16.3.3 / 15.5.24, which was moved forward after an extra critical was found), there were two RCEs: one in the Image Optimization API via AVIF, traced to the libheif library inside sharp (the patched release disabled AVIF optimisation until an upstream fix landed), and another unauthenticated RCE on Windows-hosted servers (CVE-2026-75604) that only triggered when Pages Router and App Router were mixed without Cache Components.

The pattern is consistent: the framework’s core routing and caching keep getting hardened, and the attacks keep finding the paths where untrusted bytes get turned into a file or an image. AVIF decoding, SVG escaping, image optimisation — all of them are “here’s some input, here’s a picture” operations. And OG image generation is the one where untrusted input is meant to flow in, because your social card is generated from a post title or a product name that is, in plenty of apps, written by the user.

The part I find most telling

I run a blog, and I think about this from a slightly odd angle: the OG image pipeline is exactly the kind of content pipeline that AI agents now generate at volume. The “render this headline into a shareable image” operation is becoming a default feature of whatever the models are building, and the models are building it with user-supplied strings in the input field. That’s a large, fast-growing population of apps that will pass untrusted input straight into ImageResponse without anyone thinking about it, because it’s the most sensible thing to do.

Netlify’s write-up is worth a read here. Their take is that on their serverless architecture the practical impact is limited to a crashed function invocation rather than code execution — the isolation means a poisoned request takes down one invocation, not the whole site — but they add that active exploitation could still bump your function costs. That’s a fair, understated way to describe a critical: “it’s contained, and it’ll cost you money if someone’s after you.”

What to do, and what’s coming

If you’re on 16.2.0 or later, upgrade to 16.3.6. If you’re on 15.5, move to 15.5.26 for the hardening even though the RCE isn’t in your range. Until you can patch, the guidance is straightforward: don’t put untrusted input into elements passed to ImageResponse. Escape it as XML before rendering, or keep it out of the generated image entirely. One extra note from Netlify that’s easy to miss: public deploy previews and branch deploys can stay vulnerable until they’re auto-deleted, so if you’ve got long-lived preview environments, delete the stale ones.

And here’s the kicker, because the timing is almost a joke. The out-of-band release went out on the 22nd. On the 23rd — the very next day — the same team published an advance notice for a scheduled release on 30 September addressing nine vulnerabilities: one critical, two high, five medium, one low, shipping as 16.3.7 and 15.5.27. So the security calendar for the rest of this month is: patch the RCE, then have another release land in a week. If you run Next.js in production, that’s two upgrades to schedule before the month is out, and the second one is already announced.

The lesson isn’t “Next.js is broken.” The lesson is that the attack surface has moved from the parts of the framework everyone watches to the parts that render pictures. The routers and the caches are fine. The pictures are where it’s at now.

Sources:
– Next.js Security Update for a Critical Upstream Issue (22 Sep 2026)
– Netlify: Next.js ImageResponse security release
– Satori advisory GHSA-wx4j-mvgx-mqwp — Improper escaping in Satori-generated SVG
– Next.js August 2026 Security Release
– Next.js upcoming September security release (advance notice)