Emerging Threat: (CVE-2026-94545) Next.js Remote Code Execution via ImageResponse SVG Injection
CVE-2026-94545 is a remote code execution vulnerability in the next/og ImageResponse API of Next.js, the React framework maintained by Vercel. ImageResponse generates images on the server, typically Open Graph preview cards, by rendering markup through the Satori library into SVG and then into a raster image.