A critical remote code execution vulnerability (CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j, CVSS 9.5) has been discovered in Next.js, the preeminent React web framework powering modern enterprise SaaS applications and cloud platforms. The vulnerability resides within the next/og dynamic OpenGraph image generation module, where untrusted user input passed into the upstream Satori vector rendering library escapes SVG styling blocks, triggering arbitrary JavaScript execution directly within the host Node.js application process.

The Mechanics of Dynamic OpenGraph Generation in Next.js

In modern web architecture, social platforms (Twitter, LinkedIn, Slack) fetch OpenGraph preview cards to render link thumbnails. To automate card design, Next.js introduced the ImageResponse API:

// Typical vulnerable dynamic OG route (app/api/og/route.tsx)
import { ImageResponse } from 'next/og';

export async function GET(request: Request) {
  const { searchParams } = new URL(request.url);
  const title = searchParams.get('title') || 'Default Title';

  return new ImageResponse(
    (
      <div style={{ fontSize: 48, background: 'white', width: '100%', height: '100%' }}>
        {title}
      </div>
    ),
    { width: 1200, height: 630 }
  );
}

Under the hood, ImageResponse converts HTML/JSX structures into Scalable Vector Graphics (SVG) via the Satori library, then renders the SVG into PNG bytes using Resvg.

Root Cause Analysis: Satori SVG Delimiter Escape (CWE-94)

The security boundary collapsed because prior to Next.js 16.3.6 / 15.5.26, Satori performed string interpolation on dynamic style properties and inline elements without strictly XML-escaping quotes, curly braces, and entity references.

An attacker who crafts a malicious URL query string containing inline JavaScript evaluation payloads can break out of the Satori virtual DOM abstraction:

# Attacker exploit payload transmitted via GET parameter
curl "https://target-app.com/api/og?title=%3C/div%3E%3Cstyle%3E@import%20url('javascript:global.process.mainModule.require("child_process").execSync("id")')%3C/style%3E"

When Satori parses the string inside the Node.js runtime environment, the injected styling context evaluates the payload, providing the attacker with immediate shell execution matching the privileges of the web application server (or container service account).

Scope of Impact: Node.js Runtime vs. Edge Runtime

Deployment Environment Runtime Environment Vulnerability Exposure Exploitation Mechanism
Self-Hosted Node.js Server Node.js (Standard) Critical (CVSS 9.5) Full host OS remote shell execution via child_process
Docker / Kubernetes Container Node.js Container Critical (CVSS 9.5) Container takeover; potential cloud metadata (IMDS) theft
Vercel Edge Network / Cloudflare V8 Edge Runtime Low / Mitigated Edge sandbox lacks child_process and filesystem access

Remediation Playbook for Engineering Teams

  1. Upgrade Framework Dependencies: Upgrade Next.js in package.json immediately:
    # Upgrade to patched release
    npm install next@15.5.26
    # or for Next.js 16.x projects:
    npm install next@16.3.6
  2. Switch OG Routes to Edge Runtime: If immediate dependency updates cannot be applied, configure dynamic image routes to run on the V8 Edge runtime:
    // Enforce edge runtime sandbox
    export const runtime = 'edge';
  3. Sanitize Input Parameters: Ensure all user-supplied search parameters and database records are explicitly HTML/XML-escaped before passing them into JSX blocks.