Vercel has patched a critical remote code execution vulnerability in Next.js that impacts the ImageResponse API, a built-in feature for generating Open Graph and social preview images. The flaw allows attackers to execute arbitrary code on affected servers by injecting malicious SVG content through user-controlled input.
The vulnerability affects Next.js applications that pass unsanitized user input, such as URL parameters or request data, directly into ImageResponse. When an attacker crafts a malicious SVG payload and embeds it into an image generation request, the server processes the code with elevated privileges. This execution occurs because ImageResponse uses Satori, an SVG-to-image conversion library, which can interpret embedded scripts and dynamic content. An attacker exploiting this flaw gains the same permissions as the Next.js server process, potentially allowing full system compromise.
Vercel released the patch on September 22. Organizations running Next.js applications should upgrade immediately to the patched version. The specific CVE identifier and affected version ranges have not been disclosed in preliminary reports, but Vercel's advisory recommends updating to the latest stable release.
The risk is not theoretical. Any Next.js application that dynamically generates images based on user input faces exposure. Common vulnerable patterns include passing query parameters, user-submitted text, or data from external APIs directly into ImageResponse without validation or escaping. E-commerce sites using user-provided product names in social previews, SaaS platforms generating dynamic meta images with user content, and content management systems creating social cards all represent high-risk targets.
The ImageResponse feature has gained adoption among developers building modern web applications because it enables server-side generation of rich preview images without external services. This convenience creates a false sense of security. Developers often assume the feature handles untrusted input safely, but ImageResponse itself does not sanitize or validate SVG syntax by default.
Organizations running Next.js in production should take three immediate steps. First, audit your codebase for all ImageResponse implementations and identify which ones accept user-controlled data. Second, upgrade Next.js to the patched version released on or after September 22. Third, implement input validation and sanitization for all data passed to ImageResponse, regardless of the Next.js version.
If immediate patching is not possible, temporary mitigation includes disabling ImageResponse functionality, restricting image generation to hardcoded or administrator-controlled content, or implementing a Web Application Firewall rule that blocks requests containing SVG tags or suspicious characters in parameters used by image generation endpoints.
Security researchers expect public exploitation code will emerge once the patch details propagate. This flaw falls into the category of template injection vulnerabilities, a class of attacks that consistently affects web frameworks where dynamic content generation lacks proper input handling. Next.js developers and DevOps teams should prioritize this patch above routine updates.
