CVE-2026-94545
Satori-generated SVG has improper escaping
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.
| CWE | CWE-116 |
| Vendor | vercel |
| Product | satori |
| Published | Sep 30, 2026 |
| Last Updated | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for vercel satori
Be the first to know when new unknown vulnerabilities affecting vercel satori are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
vercel / satori
>= 0.0.27, < 0.33.5
vercel / next
>= 16.2.0, < 16.3.6
References
github.com: https://github.com/vercel/satori/security/advisories/GHSA-wx4j-mvgx-mqwp github.com: https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j github.com: https://github.com/vercel/satori/pull/814 github.com: https://github.com/vercel/next.js/commit/868fad38690d72088868f299fa2bef339b26838e github.com: https://github.com/vercel/satori/commit/26a52affc031216fee5882b6e965c8dbc7ac1782 github.com: https://github.com/vercel/next.js/releases/tag/v16.3.6