critical severityConfidence highHistorical record

CVE-2026-94545 Next.js next/og ImageResponse RCE on Node.js (GHSA-vcvr-r3jv-pc5j)

Same-day Critical remote code execution in the Node.js ImageResponse implementation from next/og (CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j). Improper SVG escaping in upstream Satori can lead to RCE when attacker-controlled values are passed into SVG content, attributes, or styles. Patched Next.js is 16.3.6. Next.js 15.x is not affected by the RCE; 15.5.26 is hardening only. Edge ImageResponse is not affected.

Also tracked as CVE-2026-94545 · GHSA-vcvr-r3jv-pc5j · GHSA-wx4j-mvgx-mqwp · BREAKING: CVE-2026-94545 Next.js next/og ImageResponse RCE (GHSA-vcvr-r3jv-pc5j) · Next.js September 22 2026 security update

First observed
Sep 22, 2026
Last observed
Sep 22, 2026
Last reviewed
Sep 22, 2026
Tracking ended
Sep 22, 2026

Uncertainty and limitations

Read the evidence limits before acting on this record.

CVE-2026-94545 is listed on the GitHub advisory; NVD and cve.org may still lag. Confirm your running next version and whether Node ImageResponse handlers pass request input into SVG. Do not invent in-the-wild exploitation or KEV status.

  • Edge ImageResponse is not affected.
  • Next.js 15.x is not affected by the RCE; 15.5.26 is hardening only.
  • Apps that never pass attacker-controlled values into SVG content, attributes, or styles during Node ImageResponse generation are not affected.
  • Already on [email protected]+ is out of scope for this issue.
  • This is not the August AVIF/libheif Image Optimization RCE (GHSA-2xp9) and not CVE-2026-75604 Windows path RCE.
  • NVD and cve.org may lag behind the GitHub CVE ID assignment.
  • HOL blog is operator guidance, not a substitute for the vendor advisory.

Guard coverage and policy

What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.

Not covered, or partially covered

  • not covered

    HOL Guard CVE evidence pack for CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j 404s at correction time; campaign links the operator blog and vendor advisories.

No campaign-specific policy guidance is published.

Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.

Timeline

Reviewed events, oldest first, each tied to a verified source.

  1. Disclosure

    GHSA-vcvr-r3jv-pc5j published: Critical RCE in Next.js Node.js ImageResponse from next/og; upstream Satori GHSA-wx4j-mvgx-mqwp.

  2. Vendor action

    Next.js out-of-band releases 16.3.6 (RCE fix) and 15.5.26 (hardening only for 15.x).

  3. Update

    HOL Guard published BREAKING operator blog coverage for GHSA-vcvr-r3jv-pc5j.

  4. Correction

    GitHub advisory now lists CVE-2026-94545 for GHSA-vcvr-r3jv-pc5j; HOL blog and campaign patched in place (slug and publishedAt unchanged).

Publication clock: 1.4 hours from reviewed disclosure timestamp to HOL publication; 12-hour critical target; within target.

Reviewed artifacts

The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.

  • next@>=16.2.0 <16.3.6 (patched 16.3.6)npmpackage
  • satori@>=0.0.27 <0.33.5 (patched 0.33.5)npmpackage

Sources

Every claim on this record is traceable to the sources below.

Reviewed in full by HOL Guard Security Publishing.

Published
Last full review
Last modified

Report a correction

Record HGTC-2026-25AF3C29