CVE-2026-94545 Details
Description
Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.
A vulnerability exists in Satori, a library for converting HTML and CSS to SVG, in versions 0.0.27 prior to 0.33.5. The issue arises because the library fails to properly escape certain values before they are included in the generated SVG output. This flaw can allow crafted values to be interpreted as SVG markup, potentially leading to remote code execution, depending on how the SVG is used. The vulnerability has been patched in version 0.33.5.
Users should upgrade to Satori version 0.33.5 or later. For applications that cannot be upgraded immediately, it is advised not to render content controlled by users with Satori.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/vercel/next.js/commit/868fad38690d72088868f299fa2bef339b26838e | [email protected] | Source CodeVendor |
| https://github.com/vercel/next.js/releases/tag/v16.3.6 | [email protected] | Release NotesVendor |
| https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j | [email protected] | AdvisoryExploitRemedyVendor |
| https://github.com/vercel/satori/commit/26a52affc031216fee5882b6e965c8dbc7ac1782 | [email protected] | Source CodeVendor |
| https://github.com/vercel/satori/pull/814 | [email protected] | Source CodeVendor |
| https://github.com/vercel/satori/security/advisories/GHSA-wx4j-mvgx-mqwp | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-116 | Improper Encoding or Escaping of Output | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Vercel Satori | >= 0.0.27, < 0.33.5 (semver) |
CPE
Remediation
| |
| Vercel Next.js | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion