GHSA-vcvr-r3jv-pc5jCriticalDisclosed before NVD
Next.js: Remote Code Execution in next/og ImageResponse
📋 Description
Impact
The Node.js ImageResponse implementation from next/og is affected by an upstream vulnerability. This can lead to remote code execution.
Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation:
import { ImageResponse } from 'next/og'
export async function GET(request: Request) {
const value = new URL(request.url).searchParams.get('value') ?? ''
return new ImageResponse(
<svg width="1200" height="630">
<title>{value}</title>
</svg>
)
}
Applications using the Edge ImageResponse implementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected.
Workaround
If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js ImageResponse implementation from next/og.
🎯 Affected products1
- npm/next:>= 16.2.0, < 16.3.6
🔗 References (5)
- https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j
- https://github.com/vercel/satori/security/advisories/GHSA-wx4j-mvgx-mqwp
- https://github.com/vercel/next.js/commit/868fad38690d72088868f299fa2bef339b26838e
- https://github.com/vercel/next.js/releases/tag/v16.3.6
- https://github.com/advisories/GHSA-vcvr-r3jv-pc5j