By · Keel Automation · September 24, 2026

The patched ImageResponse is not a finished untrusted-input policy

On September 22, 2026, Netlify’s changelog warned that a critical upstream issue in Next.js `ImageResponse` (GHSA-vcvr-r3jv-pc5j / CVE-2026-94545) can lead to remote code execution when untrusted input is rendered, patched in `next` 15.5.26 and 16.3.6. On Netlify the practical blast radius is a crashed function invocation rather than code execution elsewhere, but active exploitation can still raise function costs. Mitigations are upgrade and redeploy, keep untrusted text out of `ImageResponse` (or escape it as XML) until then, and delete lingering public deploy previews and branch deploys that may stay vulnerable. The same week, Anthropic described Claude finding a novel enzyme-system hypothesis that still needs human lab ownership, and Tampa Bay Wave launched a dual-region HealthTech|X cohort with Vanderbilt Health. A patched advisory is still not the same thing as a finished untrusted-input policy that names who may feed user text into OG images, who owns the Next upgrade, who deletes old previews, and who owns function-cost alerts.

A patched advisory is not unsupervised OG authority

The fastest way to confuse a helpful security changelog with a finished operating policy is to treat "upgrade to 15.5.26" like the whole job. Someone bumps next, redeploys production, sees the advisory close in a ticket, and the loop feels complete. The quieter question arrives when a marketing page still renders visitor text into an Open Graph card, an old branch deploy stays public, or nobody owns the alert when function costs climb because someone kept feeding untrusted strings into ImageResponse.

What Netlify said about ImageResponse

On September 22, 2026, Netlify published that the Next.js team disclosed a critical severity vulnerability in an upstream dependency that can lead to remote code execution when ImageResponse renders untrusted input. The advisory is tracked as GHSA-vcvr-r3jv-pc5j / CVE-2026-94545. It is patched in next 15.5.26 and 16.3.6. Applications that do not pass untrusted input into ImageResponse are not expected to be affected.

Netlify's impact note is precise. Sites are affected only if they use ImageResponse and the generated image includes untrusted input (text, or an image loaded from the request). Sites that do not use ImageResponse, or that only render trusted content through it, are not affected. For sites that do, Netlify says the impact is limited to a crashed function invocation, not code execution elsewhere. Autoscaling means a malicious crash on one invocation does not take down other requests. Active exploitation can still increase function costs.

A warm editorial cartoon of an office worker with a tea mug holding an UNTRUSTED INPUT POLICY clipboard beside a small friendly robot offering an ImageResponse OG card, PATCHED and HOLD speech bubbles, white minimal background, bold black outlines, soft cell shading, narrative humor.

Upgrade is a map, not a finished policy stamp

Netlify's recommended path is clear: upgrade to next 15.5.26 or later, or 16.3.6 or later, then redeploy. Until you can upgrade, do not place untrusted input inside elements passed to ImageResponse. Escape it as XML before rendering, or keep it out of the generated image entirely. Publicly available deploy previews and branch deploys may remain vulnerable until they are automatically deleted, so Netlify also asks teams to consider deleting those deploys manually.

None of that is a finished untrusted-input policy. It is a map of what Netlify and Next.js already decided for the product: which versions close the RCE path, what counts as untrusted input in an OG image, how Netlify's serverless layer contains a crash, and why old previews still matter after production is patched.

Patch badge pulsing beside UNTRUSTED and HOLD stamps
A patched advisory is still not the same thing as a finished untrusted-input policy that names who may feed user text into OG images, who owns the Next upgrade, who deletes old previews, and who owns function-cost alerts.

Delete previews is not a named owner

The useful ops sentence in the changelog is the one about lingering deploys. Production can be patched while a public branch preview still runs the old binary. That sentence is a product hint, not a named owner for preview cleanup, a calendar for how long previews may live, or a stamp that says who may keep a marketing experiment online after the advisory lands.

A warm editorial cartoon of an office worker writing DELETE PREVIEW on a clipboard while a small friendly robot points at BRANCH DEPLOY and OLD PREVIEW cards with a HOLD stamp, white minimal background, bold outlines, soft cell shading, human warmth.

A day later, a different vendor story offered the same ownership reminder in another register. On September 23, 2026, Anthropic published that Claude discovered a novel enzyme system with CRISPR-like repeats after high-level human direction, with early lab follow-up by scientists. The post is useful here only as contrast: an agent hypothesis is not finished human lab ownership. The same week's Next.js advisory is the spine. Claude's enzyme note is just a reminder that "interesting result" and "someone owns the next controlled step" are still different sentences.

Local founders still need named OG owners

Tampa Bay is a useful place to hold that checklist against a different kind of "pipeline ready" story, because the region just opened another founder path that still leaves day-to-day ownership with people.

On September 23, 2026, Tampa Bay Wave announced a partnership with Vanderbilt Health through the Brock Family Center for Applied Innovation to power its 2026 HealthTech|X cohort. The dual-region program will support startups building technology for behavioral health and addiction, with in-person session weeks in Tampa and Nashville, virtual engagement between them, pitch nights in each market, and a remote Demo Day. Wave CEO Linda Olson framed the value as clinicians willing to test technology against real patients, not ideas that only work on paper. That is a stronger regional on-ramp for founders. It is not a finished untrusted-input policy for who may put visitor text into an OG image, who owns the Next bump on a Netlify site, who deletes old branch deploys, or who watches function-cost alerts after an advisory week.

A warm editorial cartoon of an office worker stamping HUMAN OWNER on an untrusted-input checklist while a small friendly robot waits with a Next.js 15.5.26 sticky note and a tea mug on the desk, white minimal background, bold outlines, soft cell shading, human warmth.

What Keel will and will not claim

I work at Keel Automation, a Tampa Bay automation agency. We build operations portals, AI integrations, workflow automation, and phone systems. Cole Junck is the owner and founder. We are not going to invent an ImageResponse incident or Netlify customer win for Keel, because we have not published one. What the public record already shows is enough: a patched ImageResponse is not a finished untrusted-input policy, a deleted preview is not unsupervised permission to skip the owner list, and a Wave cohort announcement is not a named owner for OG cards on a busy Thursday.

A dull untrusted-input checklist

The test I would run this week is intentionally dull. Write down whether any page still passes request text, query params, or user-uploaded images into ImageResponse. Write down which next version is live in production, and who owns the upgrade to 15.5.26 or 16.3.6 plus the redeploy. Write down who may publish a deploy preview, how long it may stay public, and who deletes branch deploys after an advisory. Write down who owns function-cost alerts if someone keeps probing OG routes. Write down, separately, how your local founder story treats accelerator pipelines so a patched changelog and a HealthTech cohort announcement do not get confused with a finished human ownership policy. If those answers are shrugs, you do not have a finished untrusted-input policy. You have a patched package and a hope that nobody feeds the next visitor string into an OG card.

Netlify published a clear path: upgrade, redeploy, keep untrusted input out of ImageResponse until then, and clean up old previews. Tampa Bay Wave's Vanderbilt HealthTech|X cohort keeps building founder paths that still need named humans for the messy middle. The patch can still land. The useful question is whether anyone owns the finished handoff before the next OG image pretends the advisory closed the whole desk.

Sources

  1. Netlify Changelog, "Next.js ImageResponse vulnerability," September 22, 2026, on critical upstream RCE risk when ImageResponse renders untrusted input (GHSA-vcvr-r3jv-pc5j / CVE-2026-94545), patches in next 15.5.26 and 16.3.6, Netlify impact limited to crashed function invocation with possible function-cost increase, interim guidance to escape untrusted input as XML or keep it out of generated images, and manual deletion of lingering public deploy previews and branch deploys. https://www.netlify.com/changelog/2026-09-22-nextjs-imageresponse-vulnerability/
  2. Anthropic, "Claude discovers a novel enzyme system with CRISPR-like repeats," September 23, 2026, on Claude generating an early enzyme-system hypothesis under high-level human direction, with human scientists owning laboratory follow-up (used here only as an ownership contrast, not as the article spine). https://www.anthropic.com/news/claude-discovers-novel-enzyme-system
  3. GlobeNewswire / Markets Insider, "Tampa Bay Wave Collaborates with Vanderbilt Health to Launch Dual-Region HealthTech|X Accelerator for Behavioral Health and Addiction Startups," September 23, 2026, on the 2026 HealthTech|X cohort powered with Vanderbilt Health's Brock Family Center for Applied Innovation, dual-region Tampa and Nashville sessions, pitch nights, remote Demo Day, and statements from Wave CEO Linda Olson and partners. https://markets.businessinsider.com/news/stocks/tampa-bay-wave-collaborates-with-vanderbilt-health-to-launch-dual-region-healthtech-x-accelerator-for-behavioral-health-and-addiction-startups-1036568607

Read something that sounds like your shop?

Fifteen minutes with Cole. We will tell you what we would fix first and what it costs.

Call (813) 902-4763

Related: more articles · operations portals · business phone + AI

CallText