Critical NEXT.JS Flaw Enables RCE Attacks Via Weaponized SVG File

A critical Next.js vulnerability, tracked as CVE-2026-94545, affects the Node.js ImageResponse implementation in the next/og package and could allow remote code execution by exploiting malicious SVG content during image generation. The issue affects Next.js versions 16.2.0 through versions before 16.3.6. Developers are urged to upgrade to Next.js 16.3.6, which contains the security fix. The vulnerability […]

This article has been indexed from Cyber Security News

Read the original article: