Attacker-controlled SVG values can turn a Next.js image route into unauthenticated server command execution.
Next.js applications using the Node.js next/og ImageResponse implementation to generate images from attacker-controlled values, on hosted or self-managed Node.js servers.
The path exists only where an application feeds request-controlled values into Node.js ImageResponse. Satori can serialize those values as active SVG or XML structure, allowing XInclude, entity and path data to reach the native rasterization stack and its memory-corruption chain.
Detail and 4 sources
A public reproduction executed commands twice on Next.js 16.3.5 and failed against 16.3.6 controls. The fix is published, although pre-fix images remain accepted.