#CVE-2026-94545
Critical Next.js SVG Flaw Opens Server-Side Image Routes to Remote Code Execution
A critical flaw in the Node.js implementation of Next.js ImageResponse can turn attacker-controlled SVG data into server-side code execution. Applications using affected releases should move to Next.js 16.3.6...