Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
Security

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

The Hacker News · Sep 23, 2026

Back to News
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
Security September 23, 2026

A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.