Back to Feed
VulnerabilitiesSep 23, 2026

CVE-2026-94545 – ⁠From JSX to SVG Injection

Next.js 16.3.6 update addresses CVE-2026-94545, an SVG injection vulnerability.

Summary

A new vulnerability, CVE-2026-94545, has been discovered in Next.js, allowing for JSX to SVG injection. Users running Next.js versions prior to 16.3.6 are advised to update immediately. The vulnerability does not affect Next.js 15 or the Edge ImageResponse implementation. Checkmarx's SCA tool already supports detection and will flag affected applications.

Indicators of Compromise

  • cve — CVE-2026-94545

Entities

Next.js (product)Checkmarx (vendor)