Back to all news
Security

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

The Hacker News·September 23, 2026·1 min read
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

A critical Next.js vulnerability in ImageResponse could allow attackers to run code on a server via crafted SVG input, Vercel said. The risk applies when apps put attacker-controlled values into images. Vercel fixed the flaw on September 22 in version 15.5.7.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store