An escaping flaw in the Next.js ImageResponse API lets attacker-supplied values break out into SVG markup and execute code on the server generating the image.
Read more about Emerging Threat: (CVE-2026-94545) Next.js Remote Code Execution via ImageResponse SVG Injection