CVE-2026-94545 Next.js next/og ImageResponse RCE on Node.js (GHSA-vcvr-r3jv-pc5j)
Same-day Critical remote code execution in the Node.js ImageResponse implementation from next/og (CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j). Improper SVG escaping in upstream Satori can lead to RCE when attacker-controlled values are passed into SVG content, attributes, or styles. Patched Next.js is 16.3.6. Next.js 15.x is not affected by the RCE; 15.5.26 is hardening only. Edge ImageResponse is not affected.
Also tracked as CVE-2026-94545 · GHSA-vcvr-r3jv-pc5j · GHSA-wx4j-mvgx-mqwp · BREAKING: CVE-2026-94545 Next.js next/og ImageResponse RCE (GHSA-vcvr-r3jv-pc5j) · Next.js September 22 2026 security update
- First observed
- Sep 22, 2026
- Last observed
- Sep 22, 2026
- Last reviewed
- Sep 22, 2026
- Tracking ended
- Sep 22, 2026
Record exports
Uncertainty and limitations
Read the evidence limits before acting on this record.
CVE-2026-94545 is listed on the GitHub advisory; NVD and cve.org may still lag. Confirm your running next version and whether Node ImageResponse handlers pass request input into SVG. Do not invent in-the-wild exploitation or KEV status.
- Edge ImageResponse is not affected.
- Next.js 15.x is not affected by the RCE; 15.5.26 is hardening only.
- Apps that never pass attacker-controlled values into SVG content, attributes, or styles during Node ImageResponse generation are not affected.
- Already on [email protected]+ is out of scope for this issue.
- This is not the August AVIF/libheif Image Optimization RCE (GHSA-2xp9) and not CVE-2026-75604 Windows path RCE.
- NVD and cve.org may lag behind the GitHub CVE ID assignment.
- HOL blog is operator guidance, not a substitute for the vendor advisory.
Guard coverage and policy
What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.
Not covered, or partially covered
not covered
HOL Guard CVE evidence pack for CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j 404s at correction time; campaign links the operator blog and vendor advisories.
No campaign-specific policy guidance is published.
Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.
Timeline
Reviewed events, oldest first, each tied to a verified source.
- Disclosure
GHSA-vcvr-r3jv-pc5j published: Critical RCE in Next.js Node.js ImageResponse from next/og; upstream Satori GHSA-wx4j-mvgx-mqwp.
- Vendor action
Next.js out-of-band releases 16.3.6 (RCE fix) and 15.5.26 (hardening only for 15.x).
- Update
HOL Guard published BREAKING operator blog coverage for GHSA-vcvr-r3jv-pc5j.
- Correction
GitHub advisory now lists CVE-2026-94545 for GHSA-vcvr-r3jv-pc5j; HOL blog and campaign patched in place (slug and publishedAt unchanged).
Publication clock: 1.4 hours from reviewed disclosure timestamp to HOL publication; 12-hour critical target; within target.
Reviewed artifacts
The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.
next@>=16.2.0 <16.3.6 (patched 16.3.6)npmpackagesatori@>=0.0.27 <0.33.5 (patched 0.33.5)npmpackage
Sources
Every claim on this record is traceable to the sources below.
- Next.js security update September 22 2026vendor advisory · observed September 22, 2026
- GHSA-vcvr-r3jv-pc5j / CVE-2026-94545 Next.js next/og ImageResponse RCEmaintainer advisory · observed September 22, 2026
- GHSA-wx4j-mvgx-mqwp Satori improper SVG escapingmaintainer advisory · observed September 22, 2026
- HOL Guard operator write-upother primary · observed September 22, 2026
Reviewed in full by HOL Guard Security Publishing.
- Published
- Last full review
- Last modified
Record HGTC-2026-25AF3C29