poslední zpráva
SPOJENO PŘES CVE
Next.js: PoC pubblico per lo sfruttamento della CVE-2026-94545
Disponibile Proof of Concept (PoC) per lo sfruttamento della vulnerabilità CVE-2026-94545 – già sanata dal vendor – presente in next/og ImageResponse di Next.js. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato remoto, in determinate condizioni, di eseguire codice arbitrario sui sistemi interessati.
Next.js IT FI
CVE v události 1
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-94545 | – | – | – |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.5.
Jak se o tom psalo 2
-
· CSIRT Itálie (ACN) IT nadpis události
Next.js: PoC pubblico per lo sfruttamento della CVE-2026-94545
Disponibile Proof of Concept (PoC) per lo sfruttamento della vulnerabilità CVE-2026-94545 – già sanata dal vendor – presente in next/og ImageResponse di Next.js. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato remoto, in determinate condizioni, di eseguire codice arbitrario sui sistemi interessati.
-
· zachyceno · NCSC-FI FI
Next.js - Remote Code Execution Vulnerability
Classification: Severe, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv4.0: 9.5, CVEs: CVE-2026-94545, Summary: A vulnerability in the Node.js implementation of ImageResponse can lead to remote code execution when an application passes attacker-controlled values into SVG content, attributes or styles during image generation. The vulnerability affects Next.js versions 16.2.0 through 16.3.5. Applications using the Edge implementation of ImageResponse are not affected.