Critical Node.js Vulnerability CVE-2024-27983 Allows Remote Code Execution
Key Takeaways A critical remote code execution (RCE) vulnerability, CVE-2024-27983, has been discovered in Next.js applications utilizing the Node.js implementation of ImageResponse from the next/og...
Key Takeaways
- A critical remote code execution (RCE) vulnerability, CVE-2024-27983, has been discovered in Next.js applications utilizing the Node.js implementation of
ImageResponsefrom thenext/ogpackage. - The flaw affects Next.js versions 16.2.0 through 16.3.5 and allows attackers to execute arbitrary code by injecting malicious input into dynamically generated SVG content.
- The vulnerability stems from an upstream issue in the Satori SVG generation library (CVE-2026-94545).
- A patch is available in Next.js version 16.3.6, and immediate upgrade is strongly recommended.
A severe vulnerability in Next.js could enable remote code execution (RCE) in applications that leverage the Node.js version of ImageResponse within the next/og package. This critical flaw, identified as GHSA-vcvr-r3jv-pc5j, impacts Next.js versions 16.2.0 through 16.3.5, with a corrective update released in version 16.3.6.
Table Of Content
The vulnerability manifests when applications process attacker-controlled input within SVG content, SVG attributes, or style properties during the dynamic generation of images. This is particularly problematic as developers frequently employ ImageResponse for creating Open Graph images, social media previews, and other graphics rendered on demand.
For instance, an application might read a value from a URL parameter provided by a remote attacker and embed it directly into an SVG element, such as an <title> tag. If this input is not properly sanitized, a specially crafted malicious payload could bypass intended security measures, reach the underlying image-rendering process, and ultimately facilitate remote code execution.
Understanding the Node.js ImageResponse Vulnerability
The GitHub advisory (GHSA-vcvr-r3jv-pc5j) states that this risk is specifically tied to the Node.js implementation of next/og ImageResponse. Applications using the Edge ImageResponse implementation are not affected. Similarly, applications are safe if they do not incorporate untrusted external input into SVG markup, attributes, or styles.
The root cause of this vulnerability lies in an upstream issue within Satori, the SVG generation library that forms part of the rendering chain. Satori failed to adequately escape certain values before integrating them into the final SVG output, allowing malicious data to be interpreted as valid SVG markup.
This upstream Satori flaw, tracked as CVE-2026-9455 and GHSA-wx4j-mvgx-mqwp, impacted versions 0.0.27 through 0.33.4 and was subsequently patched in version 0.33.5.
GitHub has assigned a critical rating to the Next.js issue under CVSS v4. The advisory details indicate that exploitation can occur over a network, has low attack complexity, requires no special privileges, and demands no user interaction. Successful exploitation could compromise the confidentiality, integrity, and availability of both the targeted system and any connected downstream systems.
Exploitation Scenarios and Mitigation
Attackers could target publicly accessible image-generation routes that process various forms of user-supplied data, including query-string values, POST content, profile names, or page titles. Given that Open Graph image endpoints are frequently exposed to the internet, developers must meticulously review all ImageResponse routes that accept external input.
The affected package is named “next” on npm. Next.js versions 16.2.0 through 16.3.5 are vulnerable, while version 16.3.6 includes the necessary security fix. GitHub has categorized this issue under CWE-1395, which addresses vulnerabilities arising from dependencies on insecure third-party components.
The advisory credits security researchers RaghavMaheshwari124 and rafabd1 for their diligent reporting of this critical issue. Considering the potential for unauthenticated remote code execution, organizations with affected Next.js deployments should prioritize this update with extreme urgency.
What You Should Do
- Upgrade Immediately: Organizations must upgrade Next.js to version 16.3.6 or newer as soon as possible. This version incorporates the essential fix for the vulnerable rendering path.
- Sanitize All Input: For teams unable to upgrade immediately, it is crucial to ensure that no attacker-controlled data is ever allowed to reach SVG content, attributes, or CSS styles generated via the Node.js
ImageResponseimplementation. - Audit Custom Endpoints: Developers should conduct a thorough audit of all custom image-generation endpoints, particularly those that utilize values derived from user requests (e.g., URL parameters, headers, form submissions, CMS content, or user profiles). Input validation alone may not suffice if untrusted strings can still be interpreted as markup.
- Consider Edge Implementation: Switching affected routes to the Edge
ImageResponseimplementation may reduce exposure. However, organizations should meticulously test rendering behavior and deployment compatibility before implementing such architectural changes.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.