• Sources: primary, advisory, discussion
  • Summary: Vercel published an out-of-band update on 2026-09-22 releasing Next.js 16.3.6 on Active LTS and 15.5.26 on Maintenance LTS. GHSA-vcvr-r3jv-pc5j, assigned CVE-2026-94545, is rated critical, because improper escaping in the SVG output generated by Satori, tracked upstream as GHSA-wx4j-mvgx-mqwp, can reach remote code execution through vulnerabilities in other upstream dependencies, and the fix is a dependency upgrade rather than a change in Next.js itself. Affected versions are 16.2.0 up to but excluding 16.3.6, applications using the Edge ImageResponse implementation are not affected, and 15.x is not affected by the RCE, so 15.5.26 is hardening only.
  • Why it matters: The action is narrow and mechanical, since only an app calling ImageResponse from next/og on the Node.js runtime in that version range needs the patch.

send feedback on this story