Critical

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

The Hacker News

Overview

A vulnerability in Next.js, a popular framework for building web applications, could allow attackers to execute arbitrary code on servers through its ImageResponse feature. This issue arises when user-controlled values, such as text from the request URL, are incorporated into generated images. Vercel, the company behind Next.js, announced the fix for this flaw on September 22, 2023, in a new software version. This vulnerability is particularly concerning for developers who might inadvertently expose their applications to risks by improperly handling user input. It’s crucial for users of Next.js to update to the latest version to mitigate potential exploitation.

Key Takeaways

  • Affected Systems: Next.js versions prior to the fix on September 22, 2023
  • Action Required: Upgrade to Next.
  • Timeline: Disclosed on September 22, 2023

Original Article Summary

A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version

Impact

Next.js versions prior to the fix on September 22, 2023

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Disclosed on September 22, 2023

Remediation

Upgrade to Next.js version released on September 22, 2023.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Vulnerability, Update, Critical.

Related Coverage

Hackers start exploiting critical WordPress flaw for code execution

BleepingComputer

A critical vulnerability in WordPress, identified as CVE-2026-87902, is currently being exploited by hackers. Initially, attackers were probing for sites that were vulnerable, but they have now escalated to exploiting the flaw to write files to disk that can execute shell commands when accessed. This puts numerous WordPress installations at risk, particularly those running outdated or unpatched versions of the software. Users and website administrators need to take this threat seriously, as the exploitation can lead to unauthorized access and control over affected sites. This situation underscores the importance of timely updates and security measures in maintaining website integrity.

Sep 23, 2026

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

The Hacker News

Researchers have identified a serious vulnerability affecting MikroTik routers that allows attackers to gain full administrative control without needing a password or SSH key. Known as the MikroTrick chain, this issue arises from two flaws in the RouterOS software: an SSH state-machine vulnerability (CVE-2026-67279) and an argument-injection bug in the login process (CVE-2026-86060). These vulnerabilities can be exploited on routers that are exposed to the internet, putting numerous devices at risk. Users of MikroTik routers should take immediate action to secure their devices, as the potential for unauthorized access could lead to significant data breaches or network disruptions.

Sep 23, 2026

UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks

darkreading

In the first half of 2026, the United Arab Emirates and Saudi Arabia faced a significant increase in cyberattacks, accounting for half of all incidents reported in the Gulf region. These attacks have become more complex, posing serious challenges for cybersecurity teams in both countries. The rise in incidents affects various sectors, raising concerns about the security of sensitive data and critical infrastructure. This situation highlights the urgent need for enhanced cybersecurity measures and collaboration among nations to combat these evolving threats. The implications of these attacks could be far-reaching, affecting not only businesses but also national security and public trust in digital systems.

Sep 23, 2026

How One Kubernetes YAML Can Hand Over a GCP Organization

BleepingComputer

A recent security analysis reveals that a Kubernetes user with limited permissions can exploit a flaw in Google Kubernetes Config Connector to gain control over an entire Google Cloud organization. This issue stems from a confused deputy problem, where the permissions granted to the Config Connector can be misused through a single Kubernetes YAML file. This vulnerability poses a significant risk because it allows unauthorized users to escalate their privileges and potentially compromise sensitive resources across the organization. Organizations using Google Cloud and Kubernetes need to be aware of this risk and take measures to secure their configurations. The implications of such a breach could be severe, affecting data integrity and access control.

Sep 23, 2026

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News

Threat actors have compromised two legitimate MemTensor packages on the npm and PyPI repositories to distribute a malicious program called sckit. This implant targets Windows, Linux, and macOS systems and is designed to steal credentials. Researchers from Aikido, SafeDep, Socket, and StepSecurity have reported on the affected libraries, particularly the @memtensor/memos-cloud-openclaw-plugin versions. This incident raises significant security concerns for developers and users who may have unknowingly installed these compromised packages. It's crucial for affected users to take immediate action to safeguard their systems.

Sep 23, 2026

Arista patches actively exploited VeloCloud Orchestrator zero-day

BleepingComputer

Arista Networks has addressed a zero-day vulnerability in the VeloCloud Orchestrator (VCO) On-Prem deployments, which is currently being exploited by attackers. This flaw poses a significant risk, as it allows unauthorized access to the system, potentially compromising sensitive data and network operations. Users of the VCO should apply the security patches released by Arista immediately to protect their systems. The urgency of this patching process is underscored by the fact that the vulnerability is actively being exploited in the wild. Organizations relying on VeloCloud Orchestrator must prioritize this update to mitigate the risk of an attack and safeguard their network infrastructure.

Sep 23, 2026