CVE-2026-94545

Published: Set 30, 2026 Last Modified: Set 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.

116

Improper Encoding or Escaping of Output

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability Access Control
Potential Impacts:
Modify Application Data Execute Unauthorized Code Or Commands Bypass Protection Mechanism
Applicable Platforms
Technologies: Not Technology-Specific, AI/ML, Database Server, Web Server
View CWE Details
https://github.com/vercel/next.js/commit/868fad38690d72088868f299fa2bef339b2683…
https://github.com/vercel/next.js/releases/tag/v16.3.6
https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j
https://github.com/vercel/satori/commit/26a52affc031216fee5882b6e965c8dbc7ac1782
https://github.com/vercel/satori/pull/814
https://github.com/vercel/satori/security/advisories/GHSA-wx4j-mvgx-mqwp