TL;DR
Technical details and a working proof-of-concept exploit are now public for CVE-2026-94545, a critical Next.js RCE in the next/og image API. One unauthenticated request can run commands on the server. Next.js 16.3.6 and Satori 0.33.5 fix the flaw.
- CVE: CVE-2026-94545
- CVSS: 5.3 (Medium · CVSSv4)
- Product: vercel satori
- Affected: >= 0.0.27, < 0.33.5, >= 16.2.0, < 16.3.6
- Impact: Satori-generated SVG has improper escaping
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhy It Matters
EQSTLab published a full write-up and exploit script for the bug on its CVE-2026-94545 GitHub repository. Its demo opened a root shell on a test container. Other researchers have since posted lab tools of their own.
CyCognito rates the flaw 9.5 on CVSS v4. It also found exposed assets spread across industries, led by industrials at 19.7%. So far, no source confirms exploitation in the wild. Still, a public exploit sharply shortens the time defenders have.
How the Attack Works
The next/og module builds Open Graph images. First, Satori turns JSX into SVG. However, it writes user text into that SVG without escaping it. An attacker can therefore close the element and inject their own markup.
On the Node.js runtime with sharp installed, native libraries such as libvips and libxml2 then render the SVG. EQSTLab found that crafted XML entities corrupt memory inside that parser. Because the official Node binary is non-PIE, its addresses stay fixed. As a result, the exploit needs no address leak and works on any host with the same build.
The attack is blind and crashes the worker. In practice, attackers would use a reverse shell to get output back.
Affected Versions
- Next.js 16.2.0 through 16.3.5 on the Node.js runtime with sharp
- Satori 0.0.27 up to, but not including, 0.33.5
Routes on the Edge runtime, or installs without sharp, use a sandboxed renderer. There, the Next.js RCE path does not reach code execution.
Patch and Mitigation Steps
Upgrade Now
Move to Next.js 16.3.6 and Satori 0.33.5, as the Vercel security advisory advises.
Interim Measures
- Switch next/og routes to the Edge runtime, or remove sharp.
- Keep raw user input out of ImageResponse.
- Limit outbound traffic from app servers to block reverse shells.
Finally, treat any exposed, unpatched instance as compromised. Rotate secrets the app could read and check for persistence.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!