GHSA-vcvr-r3jv-pc5j
## Impact The Node.js `ImageResponse` implementation from `next/og` is affected by an upstream vulnerability. This can lead to remote code execution. Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation: ```tsx import { ImageResponse } from 'next/og' export async function GET(request: Request) { const value = new URL(request.url).searchParams.get('value') ?? '' return new ImageResponse( <svg width="1200" height="630"> <title>{value}</title> </svg> ) } ``` Applications using the Edge `ImageResponse` implementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected. ## Workaround If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js `ImageResponse` implementation from `next/og`.
Properties
- ghsa_id
- GHSA-vcvr-r3jv-pc5j
- severity
- critical
- summary
- Next.js: Remote Code Execution in next/og ImageResponse
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-vcvr-r3jv-pc5j
- signal_observed_at
- 2026-09-30T23:58:31+00:00
- is_ghsa_only
- true
- retrieved_at
- 2026-09-30T23:58:31+00:00
- ghsa_published
- 2026-09-30T14:48:30Z
- source_url
- https://github.com/advisories/GHSA-vcvr-r3jv-pc5j
- ghsa_updated
- 2026-09-30T14:48:31Z
Related Entities (4)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph