# Next.js patches critical server code execution flaw in image generation

_Published Wednesday, September 23, 2026 at 5:07 AM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![Next.js patches critical server code execution flaw in image generation — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBxfEfPNHZcocTp156lW-VbOENuCxmLM_7xUUY5QWEppPDsL04KhbN7yaT52b_XTCXW6ensPqjF8QBXuQWUgna8jerFExtxAfkCd4NqOGcQwUn8088DU87PMD7cgYhQ-dY2_xFdwPyaKU-kD9HBx_YcjAzvzwEQzLoKUu1cRRpOT5A1luhBCE6e6ChORw/s1700-nu-rw-lo-l85-e365/next.jpg)

Vercel fixed a critical Next.js flaw on September 22 that could let attackers run code on a server through ImageResponse, the feature used to generate social preview images. The risk applies when an application places attacker-controlled values into SVG content, attributes or styles while ImageResponse runs on Node.js.

The flaw affects Next.js 16.2.0 through 16.3.5; version 16.3.6 contains the fix. Next.js 15 and the Edge version of ImageResponse are unaffected. The Hacker News found no public reports of attacks or exploit code as of September 23, and its check found that npm audit did not flag affected version 16.3.5.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html)

---
Canonical: https://techandbusiness.org/newswire/ogKb3fVg5SrrQCSb3YLpiS
Published: 2026-09-23T09:07:51.043Z
Story chronology: 2026-09-22T00:00:00.000Z
Retrieved: 2026-09-23T10:29:30.271Z
Publisher: Tech & Business (techandbusiness.org)
