Vercel Patches Critical Next.js ImageResponse RCE Traced to a Satori SVG-Escaping Flaw
Vercel shipped Next.js 16.3.6 to fix a critical, 9.5-rated remote code execution flaw in ImageResponse rooted in a Satori SVG-escaping bug, CVE-2026-94545.
Signal
36 articles covering "javascript"
Vercel shipped Next.js 16.3.6 to fix a critical, 9.5-rated remote code execution flaw in ImageResponse rooted in a Satori SVG-escaping bug, CVE-2026-94545.
Node.js 26.9.0 adds a global Worker class implementing the WHATWG Web Worker API and enables the experimental node:ffi module by default.
The indexed-btree npm package evades npm v12's install-script blocking by hiding its malware loader inside a runtime method instead, Checkmarx reports.
htmx skipped version 3 and shipped 4.0, replacing XMLHttpRequest with fetch(), building in morphing swaps, and requiring an :inherited suffix for attribute inheritance.
vlt, a JavaScript package manager built by npm's original developers, ships 1.0 with hosted registries that block malware and phased installs that stop scripts from running automatically.
pnpm 12 replaces the package manager's TypeScript/Node.js implementation with Rust, with independent Vercel Turborepo testing showing median install-time cuts of 64.4% to 90.5%.
Bun 1.4, released August 20, is the first stable version built entirely on the runtime's contested Rust rewrite, delivering 30x faster package installs and 5x lower idle CPU usage.
Node.js shipped 11 CVE fixes across three High-severity HTTP/2 and Permission Model bugs on July 29, after two delays, while EOL versions 18 and 20 get nothing upstream.
A self-propagating worm hijacked keyv and related npm packages on August 4 after a maintainer's GitHub account was breached, spreading to 1,300+ package versions.
The React team merged a work-in-progress Rust rewrite of the React Compiler, and Vercel says early Turbopack tests found 20-50% faster compilation.
npm v12 disables install scripts, Git dependencies, and remote-URL dependencies by default, closing the execution path several npm worms exploited over the past year.
Ecma International approved ECMAScript 2026 on June 30. The 17th edition of the JavaScript standard adds Math.sumPrecise, Iterator.concat, Array.fromAsync, Error.isError, Map upsert methods, Uint8Array base64 and hex conversion, and JSON.parse source access.