The record
Written from the 1 report below. Nothing here is unsourced.
- A security vulnerability in the Next.js ImageResponse feature allows remote code execution when an application embeds user-controlled data into SVG elements.
- The flaw affects versions 16.2.0 through 16.3.5 and stems from improper sanitization of inputs before they are processed by the Satori library.
- Vercel released version 16.3.6 to address the issue.
- Users are advised to upgrade immediately to mitigate the risk of exploitation.
What to watch next
- Publication of the vulnerability in the GitHub Advisory Database.
- Identification of public exploit code or reports of active exploitation.
- Clarification from Vercel on whether applications hosted on their platform are automatically protected.
Coverage1
1 report
English national1
All filed from India
Named United States · Next.js · Node.js · Satori · Vercel
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
