Public exploit code turns a Next.js image-rendering injection into native server execution.
The demonstrated stack reaches execve through sharp and the official non-PIE Node.js Linux build.
Next.js applications using Node.js ImageResponse from next/og to generate server-side images.
Unauthenticated code execution in the Next.js server context
Public exploit material closes the execution chain on a specified stack instead of leaving the consequence at native-parser corruption; only routes that feed attacker-controlled values to ImageResponse are exposed.
Detail, proof-of-concept code and 2 sources
An attacker first needs a public route that renders attacker-influenced content, attributes, or styles through next/og ImageResponse.
Satori emits the value unescaped into SVG, sharp's native renderer is corrupted, and the published ROP chain invokes execve in the server process.
The vendor advisory identifies a fixed Next.js version for the affected ImageResponse path.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Reaches end-of-life hardware
- Yes
The first two questions concern artifact acceptance and revocation mechanisms that this source-level dependency fix does not use; they are therefore recorded as unknown rather than treated as automatically complete.