criticalVulnerability

GHSA-vcvr-r3jv-pc5j

## Impact The Node.js `ImageResponse` implementation from `next/og` is affected by an upstream vulnerability. This can lead to remote code execution. Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation: ```tsx import { ImageResponse } from 'next/og' export async function GET(request: Request) { const value = new URL(request.url).searchParams.get('value') ?? '' return new ImageResponse( <svg width="1200" height="630"> <title>{value}</title> </svg> ) } ``` Applications using the Edge `ImageResponse` implementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected. ## Workaround If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js `ImageResponse` implementation from `next/og`.

Properties

ghsa_id
GHSA-vcvr-r3jv-pc5j
severity
critical
summary
Next.js: Remote Code Execution in next/og ImageResponse
last_source
GitHub Advisory Database
cve_id
GHSA-vcvr-r3jv-pc5j
signal_observed_at
2026-09-30T23:58:31+00:00
is_ghsa_only
true
retrieved_at
2026-09-30T23:58:31+00:00
ghsa_published
2026-09-30T14:48:30Z
source_url
https://github.com/advisories/GHSA-vcvr-r3jv-pc5j
ghsa_updated
2026-09-30T14:48:31Z

Related Entities (4)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/next

AFFECTS (1)

→[Software]npm/next

HAS_WEAKNESS (1)

→[Weakness]Dependency on Vulnerable Third-Party Component

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-vcvr-r3jv-pc5j — Ninja Signal Threat Intelligence | Ninja Signal