If you run a Next.js app, September has been an unusually busy month for security. There was a critical out-of-band fix on 22 September, and a second, larger release announced for 30 September. Version numbers are moving quickly, and one of them, 16.3.7, does not contain the security fixes people assume it does. Here is which version you need, what was actually fixed, and how to check your own app.
The 22 September fix: a critical issue in ImageResponse
On 22 September the Next.js team published an out-of-band security update in versions 16.3.6 (Active LTS) and 15.5.26 (Maintenance LTS). The details from the announcement:
What: a critical remote code execution issue (advisory GHSA-vcvr-r3jv-pc5j) in the Node.js implementation of
ImageResponseinnext/og. Under specific conditions, improper escaping in SVG output generated by Satori, an upstream dependency, could lead to remote code execution because of vulnerabilities in other upstream packages.Who is affected: Next.js versions
>=16.2.0 <16.3.6. Apps using the Edge implementation ofImageResponseare not affected.Next.js 15.x: not affected by the remote code execution issue, although 15.5.26 includes related hardening.
The fix is to upgrade:
npm install next@16.3.6 # for the 16.3 line
npm install next@15.5.26 # for the 15.5 line (hardening only)Then redeploy. An upgraded package.json protects nobody until the new build is live.
Am I actually exposed?
Netlify's note on the issue gives a useful way to think about it: a site is affected only if it uses ImageResponse and the image it generates includes untrusted input, such as text or an image loaded from the request. Dynamic social preview images that put a URL parameter or user-submitted title into the picture are the typical case. Sites that only use static images are unlikely to be exposed, but do not rely on that. Upgrade anyway.
To find out whether your code uses the feature at all:
grep -rn "ImageResponse" app src pages 2>/dev/null
npm ls nextThe second command shows the exact version installed, including copies pulled in by other packages.
If you cannot upgrade immediately, Netlify's interim advice is to avoid putting untrusted content in ImageResponse elements, or to escape XML before rendering, and to delete vulnerable deploy previews and branch deploys manually instead of waiting for them to expire. Treat that as a stopgap, not a fix.
The 30 September release: nine more vulnerabilities
On 23 September the team gave advance notice of a scheduled security release for 30 September. It will address nine vulnerabilities: one critical, two high, five medium and one low. The patched versions are planned as 16.3.8 and 15.5.27, published together with full advisories covering impact and affected versions.
The same post carries an important update. On 29 September, version 16.3.7 was published with a bug fix, and it does not include the security fixes. If you upgraded to 16.3.7 thinking you were covered, you are only as protected as 16.3.6, which fixes the ImageResponse issue but not the September 30 batch.
Check the Next.js blog and the project's GitHub releases page to confirm that 16.3.8 and 15.5.27 are out, and move to them (or later) as soon as they are.
A quick upgrade checklist
Run
npm ls nextand note your version and release line.Upgrade to the patched version for that line, and commit the updated lockfile.
Run your tests and build locally, especially pages that generate images or use middleware.
Redeploy production, then delete old preview and branch deployments.
Confirm the deployed version, not just the version in your repository.
Make the next one less stressful
Stay on a supported line. The announcements name 16.3 as Active LTS and 15.5 as Maintenance LTS. Older lines may not receive fixes.
Watch the advisories. Follow the Next.js blog or turn on GitHub security alerts for your repository.
Automate pull requests. Dependabot or a similar tool can open an upgrade for you the day a patch is out.
Keep upgrades small. A project that is one patch behind can upgrade in minutes. A project that is a year behind cannot.
