The Node.js ImageResponse implementation from next/og is affected by an upstream vulnerability. Under specific conditions, improper escaping in SVG output generated by Satori could lead to remote code execution due to vulnerabilities in other upstream dependencies.
https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html
https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j