Next.js patches a critical remote code execution bug in next/og
Next.js shipped an out-of-band security update on September 22, 2026 in 16.3.6 and 15.5.26. It fixes a critical issue in the Node.js ImageResponse implementation in next/og, where improper escaping in SVG output generated by Satori could lead to remote code execution. Versions from 16.2.0 up to 16.3.5 are affected. The Edge ImageResponse is not affected, and 15.x only receives hardening.

Why it matters
Open Graph image routes are usually public and take user input such as titles, which is exactly the path this bug needs.
Who should care
Next.js 16 apps that generate images with next/og on the Node.js runtime
What you can do
Upgrade to 16.3.8, which also carries the September 30 fixes, rather than stopping at 16.3.6.

