security1 publisher
Crafted Open Graph text can reach code execution in Next.js 16.2 through 16.3.5
CVE-2026-94545 lets attacker-supplied text in an Open Graph image reach Next.js dependencies. Vercel shipped the fix on September 22 in 16.3.6; a day later, npm audit still passed affected builds.
Publishers:thehackernews.com
Reality
- Evidence60
- Adoption25
- Hype gap+10
- Incentives70
- Confidence58