Skip to finding
§
High
Research / RCE
Confirmed
CVE-2026-94545

Public exploit code turns a Next.js image-rendering injection into native server execution.

The demonstrated stack reaches execve through sharp and the official non-PIE Node.js Linux build.

Affects

Next.js applications using Node.js ImageResponse from next/og to generate server-side images.

What it enables

Unauthenticated code execution in the Next.js server context

Reach an affected public Open Graph or image-generation route.→↓Place attacker-controlled text in content, attributes, or styles consumed by ImageResponse.→↓Cause Satori to emit the value unescaped into SVG supplied to the native rasterizer.→↓Trigger native-parser memory corruption in the demonstrated sharp rendering stack.→↓Use the public non-PIE Node.js ROP chain to invoke execve in the server process.
Why this matters

Public exploit material closes the execution chain on a specified stack instead of leaving the consequence at native-parser corruption; only routes that feed attacker-controlled values to ImageResponse are exposed.

Detail, proof-of-concept code and 2 sources
Required access

Internet access to an affected application route that renders attacker-influenced values with next/og ImageResponse

Affected versions

Next.js 16.2.0 through 16.3.5 when using the affected Node.js ImageResponse path

Proof of concept

Public exploit code →

An attacker first needs a public route that renders attacker-influenced content, attributes, or styles through next/og ImageResponse.

Satori emits the value unescaped into SVG, sharp's native renderer is corrupted, and the published ROP chain invokes execve in the server process.

The vendor advisory identifies a fixed Next.js version for the affected ImageResponse path.

Evidence
The vendor advisory establishes the vulnerable ImageResponse path and fixed version.Public exploit material demonstrates command execution against Next.js 16.3.5, sharp 0.35.4, and the official non-PIE Node.js 24.20.0 Linux build.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, October 4, 2026