Skip to finding
important · Remote code execution

Attacker-controlled SVG values can turn a Next.js image route into unauthenticated server command execution.

Affects

Next.js applications using the Node.js next/og ImageResponse implementation to generate images from attacker-controlled values, on hosted or self-managed Node.js servers.

The path exists only where an application feeds request-controlled values into Node.js ImageResponse. Satori can serialize those values as active SVG or XML structure, allowing XInclude, entity and path data to reach the native rasterization stack and its memory-corruption chain.

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 24, 2026