Topic

RCE

Latest RCE coverage — 1 article.

Critical Next.js ImageResponse RCE (CVE-2026-94545): A 9.5 That Hides in Your Image Generation
RCE · Next.js · Security Alert · Security · Vulnerability · CVE

Critical Next.js ImageResponse RCE (CVE-2026-94545): A 9.5 That Hides in Your Image Generation

Vercel has disclosed a critical remote code execution flaw in the Node.js implementation of ImageResponse in Next.js, tracked as CVE-2026-94545. It carries a CVSS of 9.5, and it is network-reachable with no authentication and no user interaction. But whether it affects you comes down to a detail that a version check alone will not answer: whether untrusted data reaches the SVG your app generates. This is a case where "am I running an affected version" is only half the question. What the vulner

3 min read