BetaWeekly digests are a beta — we're trying something new. Feedback welcome.
Next.js patches a remote code execution bug as SvelteKit 3 nears release
September 21–27, 2026
Next.js shipped a security release fixing a remote code execution vulnerability in its OG image renderer, alongside a batch of canary work on Turbopack and upgrade tooling. SvelteKit's 3.0 prereleases kept cutting breaking changes through the adapters, and EAS CLI added Supabase advisor checks and App Store Connect API key support.
Next.js closes an RCE in next/og
The week's most urgent item came from Next.js: a remote code execution vulnerability in next/og ImageResponse, tracked as GHSA-vcvr-r3jv-pc5j. Any app generating OG images from untrusted input should treat this as a drop-everything upgrade. Alongside it, the v15 line got a backported security hardening pass for next/og, so teams stuck on the older major aren't left exposed.
The OG renderer got attention from the hardening side too — earlier in the week the same surface had been tightened with stricter SVG serialization in the canary line, an indication that image generation has become a security-relevant boundary rather than just a convenience API.
Upgrade tooling becomes a first-class feature
A clear thread through Next.js's canary churn is that the framework is now opinionated about how you upgrade it. DevTools surfaces security upgrade insights, drawing on focused npm advisories and nudging only when an upgrade is actually ready. The agentic upgrade path expanded to prerelease channels and can now run without Git, and earlier iterations defaulted agentic upgrades to a separate worktree and narrowed the context handed to the upgrade agent. The next analyze command was promoted out of experimental in the same stretch.
Turbopack and prerendering stabilization
Beneath the tooling, the canary line spent the week grinding on correctness. Turbopack picked up support for additionalRoots in deployment adapters and learned to let webpack loaders cross filesystem roots, while facade splits are no longer created solely for export mangling. Two separate ModuleId regressions were fixed, the second one landing after an earlier fix regressed again, and a yet earlier pass had already tackled a different instance plus missing content in Cached Navigations.
Partial prerendering saw steady progress: error boundaries are now preserved in on-demand prerenders, server actions no longer hang after navigating to PPR pages, and the unstable_ensureStatic option gained nesting validation after being scaffolded as a segment config. Elsewhere, strict route matching switched on by default — a behavioral change worth reading the notes on before upgrading — and a prefetch loop triggered by redirecting predicted routes was squashed. Two experiments came and went: custom webpack support arrived and was reverted shortly after, and work continued on preparing use cache for static root-param tracking. Rounding out the churn were Turbopack chunking and GC tuning and deferred aggregation graph management.
SvelteKit 3 breaks adapters into shape
SvelteKit's 3.0 prereleases hardened the boundary between kit and its deployment adapters. The Node adapter now records static assets at build time and refuses to serve files added later, validating them with content-hash ETags and restricting them to GET and HEAD. Bun's adapter switched to building the server with Vite instead of a second Bun.build pass, then bundle Svelte libraries in dependencies rather than externalizing them and always bundles dev dependencies. The Node adapter made the same dev-dependency fix and then extended bundling to Svelte libraries in dependencies. Netlify's adapter now writes static files from the publish option rather than reading netlify.toml.
In kit itself, query parameters beginning with x-sveltekit- are now rejected, which matters if you built anything custom against that reserved prefix. That release also generates types when the dev server starts and supports bigint route params. Later prereleases fixed a hashchange leaking to app listeners during focus handling, kept a form.for instance registered across derived reconnects, blurred focused SVG elements before navigation updates the DOM, and made cookie options optional.
EAS CLI adds Supabase and App Store Connect integrations
Expo's EAS CLI added eas integrations:supabase:advisors, listing unresolved Supabase Security and Performance Advisor findings for the linked project, and now accepts individual App Store Connect API keys for submissions, TestFlight setup, and metadata — a real convenience for teams that would rather not hand over a shared key. The same release added --build-fingerprint to eas simulator and fixed a Role: undefined display bug for the Release Manager role.
Releases covered27
- @sveltejs/adapter-node@6.0.0-next.13 (opens in new tab)
- @sveltejs/adapter-bun@1.0.0-next.3 (opens in new tab)
- @sveltejs/adapter-bun@1.0.0-next.5 (opens in new tab)
- @sveltejs/adapter-bun@1.0.0-next.4 (opens in new tab)
- @sveltejs/adapter-node@6.0.0-next.14 (opens in new tab)
- @sveltejs/adapter-node@6.0.0-next.15 (opens in new tab)
- @sveltejs/adapter-netlify@7.0.0-next.12 (opens in new tab)
- @sveltejs/kit@3.0.0-next.28 (opens in new tab)
- @sveltejs/kit@3.0.0-next.30 (opens in new tab)
- @sveltejs/kit@3.0.0-next.29 (opens in new tab)
- Next.js v16.3.6 patches remote code execution in next/og ImageResponse (opens in new tab)
- Next.js v15.5.26 hardens next/og security (opens in new tab)
- Next.js v16.4.0-canary.39 fixes prefetch loop and hardens next/og SVG serialization (opens in new tab)
- Next.js v16.4.0-canary.51 adds security upgrade insights to DevTools (opens in new tab)
- Next.js v16.4.0-canary.50 expands agentic upgrade support on prerelease channels (opens in new tab)
- Next.js v16.4.0-canary.41 preserves error boundaries in on-demand prerenders (opens in new tab)
- Next.js v16.4.0-canary.45 adds additionalRoots for Turbopack deployment adapters (opens in new tab)
- Next.js v16.4.0-canary.42 promotes next analyze command (opens in new tab)
- Next.js v16.4.0-canary.49 adjusts facade splitting and Turbopack loader roots (opens in new tab)
- Next.js v16.4.0-canary.43 tunes Node server chunking and fixes Turbopack module regression (opens in new tab)
- Next.js v16.4.0-canary.40 fixes Turbopack ModuleId regression (opens in new tab)
- Next.js v16.4.0-canary.48 fixes Server Actions hang and Edge SSR metadata streaming (opens in new tab)
- Next.js v16.4.0-canary.38 enables strict route matching by default (opens in new tab)
- Next.js v16.4.0-canary.46 reverts experimental custom webpack support (opens in new tab)
- Next.js v16.4.0-canary.47 prepares use cache for static root-param tracking (opens in new tab)
- Next.js v16.4.0-canary.44 defers turbo-tasks GC aggregation graph work (opens in new tab)