CVE-2026-94545

LOW

Signal is active with 8 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 9 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 8 mentions on most recent observed day (2026-09-23)
  • 9 total mentions across 2 days

Deep dive

Activity timeline9 mentions / 2d
02468Mentions · 2026-09-22: 1Mentions · 2026-09-23: 809-2209-23
Referenced assets5 URLs
Full discourse9 posts
  • sy.br1d@rafabd1_

    We recently found a new RCE chain affecting the Node.js ImageResponse implementation in Next.js. Vercel has published CVE-2026-94545. Next.js versions from 16.2.0 through 16.3.5 are affected. Upgrade to Next.js 16.3.6. I'll share more details soon, once the remaining upstream advisories are out! Credit also to @ragrocks77, who discovered this together with me Post: https://nextjs.org/blog/nextjs-security-update-september-22-2026

    328021111212.2K
    1.8K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CRITICAL NEXT.JS RCE DISCLOSED — ATTACKER-CONTROLLED SVG DATA CAN LEAD TO SERVER CODE EXECUTION Vercel has disclosed a critical remote-code-execution vulnerability affecting the Node.js implementation of ImageResponse in Next.js. • CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j • CVSS 9.5 Critical • Affects Next.js >=16.2.0 and <16.3.6 • Exploitation is network-accessible and requires no authentication or user interaction, but requires an affected application configuration • Applications are vulnerable when attacker-controlled values reach SVG content, attributes or styles rendered through next/og ImageResponse • Successful exploitation can lead to remote code execution on the Node.js server • The Edge implementation of ImageResponse is NOT affected • Applications that never place attacker-controlled data into generated SVG content, attributes or styles are also not affected • Fixed in Next.js 16.3.6 • Vercel recommends removing untrusted SVG input from Node.js ImageResponse as a workaround where immediate upgrading is impossible • No confirmed in-the-wild exploitation has been identified at this time ⚠️ Analyst Note: The interesting attack surface is dynamic image generation. Open Graph/social-preview images often incorporate URL parameters, usernames, titles or other externally supplied content — exactly the type of data that can become attacker-controlled. Internet-facing Next.js applications using server-side ImageResponse should therefore review not only their framework version but whether untrusted values flow into SVG generation. Original Vercel / Next.js security advisory: https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j #NextJS #Vercel #CVE202694545 #RCE #WebSecurity #Vulnerability #ThreatIntel #DDW #DarkWeb

    621016311513.1K
    204.8K followersView on X
  • The Hacker News@TheHackersNews

    ‼️ Next.js patched a critical ImageResponse flaw that can lead to server code execution. "CVE-2026-94545" affects 16.2.0 through 16.3.5 on Node.js when attacker-controlled values reach generated SVG. The fix is 16.3.6. Inside the bug: https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html

    4210873220.1K
    2.4M followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Vercel fixed a critical Next.js RCE vulnerability in image generation. Update to patch this Next.js RCE vulnerability and secure your apps. #Nextjs #CVE202694545 #RCE #Cybersecurity #WebSecurity #Vulnerability https://securityonline.info/nextjs-rce-vulnerability-cve-2026-94545/

    00010220
    13.0K followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨 Critical - Remote Code Execution in next/og ImageResponse (CVE-2026-94545) A critical Remote Code Execution (RCE) vulnerability exists in the Node.js ImageResponse implementation of next/og due to an upstream issue. An attacker can exploit this by injecting malicious user-controlled input into SVG content, attributes, or styles during image generation. 👉 Affected: next (npm) versions >= 16.2.0 and < 16.3.6 (Patched: 16.3.6).

    0001048
    305 followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 ALERT — CRITICAL NEXT.JS RCE DATE: September 22, 2026 CONFIRMED BY: Next.js / Vercel PRODUCT: Next.js next/og ImageResponse CVE: CVE-2026-94545 SEVERITY: Critical — CVSS 9.5 IMPACT: Attacker-controlled values rendered through the Node.js ImageResponse implementation can, under affected conditions, lead to Remote Code Execution on the server. AFFECTED VERSIONS: Next.js >=16.2.0 and <16.3.6 FIXED VERSION: Next.js 16.3.6 EXPLOITATION STATUS: RCE impact confirmed by the vendor. No confirmed in-the-wild exploitation found at this time. URGENT ACTION: Upgrade to Next.js 16.3.6 immediately. Until patched, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by Node.js ImageResponse. SOURCE: https://nextjs.org/blog/nextjs-security-update-september-22-2026 TECHNICAL ADVISORY: https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j #CyberSecurity #InfoSec #ThreatIntel #NextJS #Vercel #CVE #CVE202694545 #RCE #WebSecurity #Vulnerability #SecOps

    0000018
    219 followersView on X
  • Hazem Omier@hazemomier

    قصة أمن سريعة (Next.js / CVE-2026-94545 — سبتمبر ٢٠٢٦): ثغرة في ImageResponse تقدر توصل لتنفيذ كود على السيرفر لما قيم مهاجِم تعدّي لمسار معالجة الصور على Node (١٦.٢.٠ → ١٦.٣.٥). مش «bug UI». ده مسار render بقى سطح هجوم على الـ app server. الدرس لـ CTO: ١) ثبّت الإصدار فوق الباتش ٢) ما تدّيش لوكيل صلاحية deploy/upgrade من غير بوابة موافقة ٣) أي مسار يقبل input ويولّد صورة/PDF جوه Node = منطقة حساسة زي الـ RCE الباتش أسرع من الـ postmortem.

    0000045
    400 followersView on X
  • VulnTracker@vuln_tracker

    Critical Next.js RCE: CVE-2026-94545 (CVSS 9.5) in the Node.js ImageResponse from next/og. No auth, no user interaction. The catch: being on an affected version (16.2.0-16.3.5) isn't enough to be exposed. You're only vulnerable if attacker-controlled data reaches the SVG you generate. Who's actually affected: https://vulntracker.io/blog/nextjs-imageresponse-rce-cve-2026-94545/

    0000075
    762 followersView on X
  • loatheb@revan_zhang

    ⚠️ Next.js 严重安全更新(CVSS 9.5 评分,CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j) next/og 模块的 ImageResponse 方法存在可远程代码执行漏洞。受影响版本 >=16.2.0 <16.3.6,修复版本 16.3.6。 根因在上游依赖 Satori 其生成的 SVG 输出转义不当,在特定条件下会触碰更下层图像处理依赖中的漏洞,从而形成 RCE 链。官方修复方式是升级这批上游依赖。 影响范围 - 仅 Node.js runtime 下的 ImageResponse 受影响 - Edge runtime 的 ImageResponse 不受影响 - 15.x 不受此 RCE 影响,15.5.26 仅为相关加固 - 触发前提:有攻击者可控的输入进入 og 渲染内容(title / 文本 / 样式等) 该 Advisory 目前以仓库级发布,部分 npm audit / Dependabot 可能尚未告警,建议以官方版本号手动核对,勿只依赖自动化扫描。

    00000132
    411 followersView on X

Explore more