A working PoC exploit has been publicly released for CVE-2026-94545, a critical remote code execution flaw in the Next[.]js next/og image API. The disclosure notes that one unauthenticated request can execute commands on the affected server. The advisory lists Next[.]js 16.2.0–16.3.5 on Node[.]js runtimes with the sharp package, and Satori 0.0.27 up to but not including 0.33.5, as affected. Edge-runtime routes or installations without sharp use a sandboxed renderer and are not exposed to the RCE path.
While initial threat assessments suggested high severity (CyCognito rates CVSS v4 at 9.5 and EQSTLab published a full write‑up with an exploit script, including a root shell in a test container), the published material also notes that there have been no confirmed cases of exploitation in the wild to date.
How the attack works, as described in the sources, hinges on the next/og module’s Open Graph image rendering. Satori converts JSX to SVG and writes user-provided text into the SVG without escaping. An attacker can terminate the SVG element and inject their own markup. On Node[.]js with libvips/libxml2 present, crafted XML entities can corrupt memory in the rendering pipeline, enabling an attacker to achieve code execution without an address leak.
Practically, attackers could run a reverse shell to exfiltrate output. The recommended mitigations are to upgrade to Next[.]js 16.3.6 and Satori 0.33.5, or to move next/og routes to the Edge runtime, or remove sharp, with additional guidance to keep raw user input out of ImageResponse and to limit outbound traffic.