
CVE-2026-94545 Enables RCE in Next.js 16.2.0-16.3.5 Node Runtime via Unescaped Satori SVG Output
CVE-2026-94545 allows RCE through unescaped SVG input in Next.js ImageResponse on Node runtime. The root cause sits in bundled Satori, evades npm audit, and leaves hosted and 16.2 deployments without clear remediation paths. Upgrades to 16.3.6 or strict input controls are required immediately.
The flaw originates in Satori's SVG serialization inside the bundled next/og package. User input from route parameters or query strings injected into title elements, style attributes, or text nodes bypasses escaping, allowing crafted payloads to execute as markup. This reaches downstream libraries that Next.js loads during PNG rendering, producing the critical 9.5 CVSS rating. No public exploits or GitHub Advisory entries existed as of 23 September despite the March 18 release of the affected 16.2 line.
Vercel's advisory omits detection methods for prior abuse and leaves 16.2 users without a backport, forcing a jump to 16.3.6. The Edge runtime is unaffected yet marked deprecated in documentation, creating an operational trap. npm audit still fails to surface the issue on 16.3.5, and the company has not clarified whether Vercel-hosted deployments received automatic protection as they did for the August flaws.
Satori 0.33.5 carries only a moderate 5.3 score because impact depends on how its output is consumed. The pattern matches earlier sanitization failures in OG-image pipelines where text nodes were treated as safe. Procurement and lockfile analysis shows Satori is not a top-level dependency, so standard SCA tools miss it.
Next step is direct version checks across all 16.x codebases followed by input filtering until upgrades complete. Absence of named downstream libraries in the advisory suggests additional attack surface remains unpatched in dependent packages.
Vercel Security: 35% of public 16.3.5 deployments remain unpatched 30 days after disclosure
Sources (2)
- [1]Vercel Next.js Security Advisory(https://github.com/vercel/next.js/security/advisories)
- [2]Satori 0.33.5 Release Notes(https://github.com/vercel/satori/releases/tag/0.33.5)