---
id: GHSA-vcvr-r3jv-pc5j
title: 'Next.js: Remote Code Execution in next/og ImageResponse'
summary: 'Next.js: Remote Code Execution in next/og ImageResponse'
severity: critical
cwe:
  - CWE-1395
vendor: next
product: next
ecosystem: npm
affected:
  - 'next >= 16.2.0, < 16.3.6'
patched:
  - next 16.3.6
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T14:48:31Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-vcvr-r3jv-pc5j'
references:
  - url: 'https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j'
  - url: 'https://github.com/vercel/satori/security/advisories/GHSA-wx4j-mvgx-mqwp'
  - url: >-
      https://github.com/vercel/next.js/commit/868fad38690d72088868f299fa2bef339b26838e
  - url: 'https://github.com/vercel/next.js/releases/tag/v16.3.6'
  - url: 'https://github.com/advisories/GHSA-vcvr-r3jv-pc5j'
tags:
  - ghsa
  - npm
ingestedAt: '2026-09-30T15:07:05.372Z'
---

## Overview

## Impact

The Node.js `ImageResponse` implementation from `next/og` is affected by an upstream vulnerability. This can lead to remote code execution.

Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation:

```tsx
import { ImageResponse } from 'next/og'

export async function GET(request: Request) {
  const value = new URL(request.url).searchParams.get('value') ?? ''

  return new ImageResponse(
    <svg width="1200" height="630">
      <title>{value}</title>
    </svg>
  )
}
```

Applications using the Edge `ImageResponse` implementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected.

## Workaround

If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js `ImageResponse` implementation from `next/og`.

## Affected packages

- `next >= 16.2.0, < 16.3.6`

## Remediation

Upgrade to a patched release:

- `next 16.3.6`
