{"type":"bundle","id":"bundle--d13369fa-9078-555f-900e-4db7702540fb","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--fa6f497f-d2c6-51b4-9cae-648db7db4fb0","created":"2026-09-22T18:25:57.288Z","modified":"2026-09-22T18:25:57.288Z","name":"CVE-2026-94545 Next.js next/og ImageResponse RCE on Node.js (GHSA-vcvr-r3jv-pc5j)","description":"Same-day Critical remote code execution in the Node.js ImageResponse implementation from next/og (CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j). Improper SVG escaping in upstream Satori can lead to RCE when attacker-controlled values are passed into SVG content, attributes, or styles. Patched Next.js is 16.3.6. Next.js 15.x is not affected by the RCE; 15.5.26 is hardening only. Edge ImageResponse is not affected.","aliases":["CVE-2026-94545","GHSA-vcvr-r3jv-pc5j","GHSA-wx4j-mvgx-mqwp","BREAKING: CVE-2026-94545 Next.js next/og ImageResponse RCE (GHSA-vcvr-r3jv-pc5j)","Next.js September 22 2026 security update"],"first_seen":"2026-09-22T17:03:51.000Z","last_seen":"2026-09-22T18:22:46.517Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"Next.js security update September 22 2026","url":"https://nextjs.org/blog/nextjs-security-update-september-22-2026"},{"source_name":"GHSA-vcvr-r3jv-pc5j / CVE-2026-94545 Next.js next/og ImageResponse RCE","url":"https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j"},{"source_name":"GHSA-wx4j-mvgx-mqwp Satori improper SVG escaping","url":"https://github.com/vercel/satori/security/advisories/GHSA-wx4j-mvgx-mqwp"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/ghsa-vcvr-r3jv-pc5j-nextjs-og-imageresponse-rce"}]}]}