---
title: 「Next.js」图像生成模块存在RCE漏洞
url: https://www.dataloco.com/zh/nextjsrce
published: 2026-09-28T06:03:18+00:00
language: zh
section: 安全
source: https://www.security-next.com/190616
organizations: imageresponse, next.js, node.js, rce
publisher: Dataloco
---

# 「Next.js」图像生成模块存在RCE漏洞

「Next.js」的图像生成模块「ImageResponse」的「Node.js实现」被发现存在安全漏洞。相关的修正版已经发布。

该漏洞编号为「CVE-2026-94545」，可能导致远程代码执行。攻击者可以向生成图像时的SVG内容、属性和样式传递可控值，从而导致远程代码执行的风险。

根据通用漏洞评分系统「CVSSv4.0」，该漏洞的基础分数为「9.5」，被评为四个等级中最严重的「关键（Critical）」。

开发团队在「Next.js 16.3.6」中修复了该漏洞，若用户无法立即更新，则建议采取相应的规避措施。

## This story in other languages

- [Svenska](https://www.dataloco.com/sv/sarbarhet-i-nextjs-bildmodul-kan-leda-till-rce)
- [Bahasa Indonesia](https://www.dataloco.com/id/modul-gambar-nextjs-terpapar-celah-eksekusi-kode-jarak-jauh)
- [हिन्दी](https://www.dataloco.com/hi/nextjs-ka-imaja-janarashana-madayal-ma-rce-sa-sabthhata-sarakashha-kamajaraya)
