XDLXDL
⚠️ CVE-2026-94545 (CVSS 9.5) ⚠️ Your Next.js OG image endpoint can hand an attacker a shell. 😱 If you use next/og on the Node runtime with sharp installed (what Next recommends for prod), one unauthenticated POST to that route runs commands on your server. Here's why: Satori · XDL