On September 22, 2026 the Next.js team shipped an out-of-band security update for a critical issue in next/og, the module many Next.js sites use to draw their social cards. A day later they announced a scheduled release for September 30 with nine more fixes. If your site generates OG images, put both dates in your plan.
The advisory
| Field | Detail |
|---|---|
| Advisory | GHSA-vcvr-r3jv-pc5j, CVE-2026-94545 |
| Severity | Critical, CVSS 9.5: remote code execution |
| Affected | Next.js >=16.2.0 <16.3.6 |
| Fixed in | 16.3.6 (Active LTS); 15.5.26 adds hardening only |
| Upstream | GHSA-wx4j-mvgx-mqwp in Satori, Moderate 5.3, fixed in 0.33.5 |
| Not affected | the Edge ImageResponse, Next.js 15.x, and apps that pass no attacker-controlled values |
Satori turns the JSX you pass to ImageResponse into SVG, and it didn't escape certain values before writing them out. The advisory states the precondition: the attack needs "attacker-controlled values" in the SVG's content, attributes or styles, rendered by the Node.js implementation. An attacker could chain that escaping gap with other upstream dependencies to reach remote code execution.
Triage in five steps
Step 1
Check your version:npm ls next. Anything from 16.2.0 up to 16.3.5 is in range.Step 2
Find the image routes: search forImageResponseandnext/og, and foropengraph-imageandtwitter-imagefiles.Step 3
Check the runtime. Only the Node.js implementation is affected; routes on the Edge runtime are not.Step 4
Check the inputs. Does any request value, such as a query string, a path segment or a user's profile name, reach the JSX?Step 5
Upgrade to 16.3.6 and redeploy.
If you can't upgrade today, the advisory's workaround is to stop passing attacker-controlled values into the SVG. Accept an id and look the text up on the server instead of accepting the text itself:
import { ImageResponse } from "next/og";
export async function GET(
_request: Request,
{ params }: { params: Promise<{ slug: string }> },
): Promise<Response> {
// Before: const title = new URL(_request.url).searchParams.get("title");
const { slug } = await params;
const post = await getPostBySlug(slug);
if (!post) return new Response("Not found", { status: 404 });
return new ImageResponse(<Card title={post.title} />, { width: 1200, height: 630 });
}
September 30
The scheduled release will address nine vulnerabilities:
- critical
- 1
- high
- 2
- medium
- 5
- low
- 1
The planned versions are 16.3.7 and 15.5.27, with full advisories published at release time. Taking 16.3.6 now doesn't spare you the second upgrade. The September 22 details are already public, and the September 30 ones aren't yet, so patch now and block an hour on the 30th for 16.3.7.
Counting September 30, that's three Next.js security releases since August 25, and December 2025's React Server Components advisories came in two rounds as well. I keep a patch lane that can ship a dependency bump the same day.
Sources
- Next.js Security Update for a Critical Upstream Issue, Next.js, September 22, 2026
- GHSA-vcvr-r3jv-pc5j, Next.js advisory
- GHSA-wx4j-mvgx-mqwp, Satori advisory
- Upcoming Next.js September Security Release, Next.js, September 23, 2026
- August 2026 Security Release, Next.js
Volodymyr Chornous

