GHSA-vcvr-r3jv-pc5jCritical▾ MidnightNext.js: Remote Code Execution in next/og ImageResponse
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Node.js ImageResponse implementation from next/og is affected by an upstream vulnerability. This can lead to remote code execution.
Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation:
import { ImageResponse } from 'next/og'
export async function GET(request: Request) {
const value = new URL(request.url).searchParams.get('value') ?? ''
return new ImageResponse(
<svg width="1200" height="630">
<title>{value}</title>
</svg>
)
}
Applications using the Edge ImageResponse implementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected.
If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js ImageResponse implementation from next/og.
next >= 16.2.0, < 16.3.6Upgrade to a patched release:
next 16.3.6Connected by shared product, vendor, weakness, or advisory.
GHSA-2xp9-vwfh-vxw4CriticalNext.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
CVE-2026-75604Critical· 9.0Next.js is a React framework for building full-stack web applications
CVE-2026-64648MediumNext.js: Cache confusion of response bodies for requests with bodies
CVE-2026-64649HighNext.js: Server-Side Request Forgery in Server Actions on custom servers
CVE-2026-64641HighNext.js: Denial of Service in App Router using Server Actions
CVE-2026-64642HighNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale