{
  "id": 9293478,
  "title": "Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input",
  "url": "https://urgent.news/2026/09/23/critical-next-js-imageresponse-flaw-can-lead-to-server-code-execution",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-23T07:04:40.000Z",
  "source": {
    "name": "The Hacker News",
    "slug": "the-hacker-news",
    "url": "https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html"
  },
  "original_language": "en",
  "account": null,
  "summary": "A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Hacker News",
        "title": "WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers",
        "url": "https://urgent.news/2026/09/22/wordpress-issues-patch-for-critical-flaw-that-can-enable-code",
        "published": "2026-09-22T18:03:10.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}