---
collection: frontend-frameworks
collection_name: Frontend Frameworks
week_start: 2026-09-21
title: Next.js patches a remote code execution bug as SvelteKit 3 nears release
release_count: 27
generated: 2026-09-28
canonical: https://releases.sh/collections/frontend-frameworks/digest/2026-09-21
---

# Next.js patches a remote code execution bug as SvelteKit 3 nears release

Next.js shipped a security release fixing a remote code execution vulnerability in its OG image renderer, alongside a batch of canary work on Turbopack and upgrade tooling. SvelteKit's 3.0 prereleases kept cutting breaking changes through the adapters, and EAS CLI added Supabase advisor checks and App Store Connect API key support.

### Next.js closes an RCE in next/og

The week's most urgent item came from Next.js: a [remote code execution vulnerability in next/og ImageResponse](https://github.com/vercel/next.js/releases/tag/v16.3.6), tracked as GHSA-vcvr-r3jv-pc5j. Any app generating OG images from untrusted input should treat this as a drop-everything upgrade. Alongside it, the v15 line got a backported [security hardening pass for next/og](https://github.com/vercel/next.js/releases/tag/v15.5.26), so teams stuck on the older major aren't left exposed.

The OG renderer got attention from the hardening side too — earlier in the week the same surface had been tightened with [stricter SVG serialization](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.39) in the canary line, an indication that image generation has become a security-relevant boundary rather than just a convenience API.

### Upgrade tooling becomes a first-class feature

A clear thread through Next.js's canary churn is that the framework is now opinionated about how you upgrade it. DevTools [surfaces security upgrade insights](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.51), drawing on focused npm advisories and nudging only when an upgrade is actually ready. The agentic upgrade path [expanded to prerelease channels](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.50) and can now run without Git, and earlier iterations [defaulted agentic upgrades to a separate worktree](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.41) and [narrowed the context handed to the upgrade agent](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.45). The `next analyze` command was [promoted out of experimental](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.42) in the same stretch.

### Turbopack and prerendering stabilization

Beneath the tooling, the canary line spent the week grinding on correctness. Turbopack picked up support for [additionalRoots in deployment adapters](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.45) and learned to [let webpack loaders cross filesystem roots](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.49), while [facade splits are no longer created solely for export mangling](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.49). Two separate ModuleId regressions were fixed, the second one landing [after an earlier fix regressed again](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.43), and a yet earlier pass had already tackled [a different instance plus missing content in Cached Navigations](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.40).

Partial prerendering saw steady progress: [error boundaries are now preserved in on-demand prerenders](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.41), [server actions no longer hang after navigating to PPR pages](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.48), and the [`unstable_ensureStatic` option gained nesting validation](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.40) after being [scaffolded as a segment config](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.39). Elsewhere, [strict route matching switched on by default](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.38) — a behavioral change worth reading the notes on before upgrading — and a [prefetch loop triggered by redirecting predicted routes](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.39) was squashed. Two experiments came and went: [custom webpack support arrived](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.41) and was [reverted shortly after](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.46), and work continued on [preparing `use cache` for static root-param tracking](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.47). Rounding out the churn were [Turbopack chunking and GC tuning](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.44) and [deferred aggregation graph management](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.44).

### SvelteKit 3 breaks adapters into shape

SvelteKit's 3.0 prereleases hardened the boundary between kit and its deployment adapters. The Node adapter now [records static assets at build time and refuses to serve files added later](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-node%406.0.0-next.13), validating them with content-hash ETags and restricting them to GET and HEAD. Bun's adapter [switched to building the server with Vite instead of a second Bun.build pass](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-bun%401.0.0-next.3), then [bundle Svelte libraries in dependencies rather than externalizing them](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-bun%401.0.0-next.5) and [always bundles dev dependencies](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-bun%401.0.0-next.4). The Node adapter made [the same dev-dependency fix](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-node%406.0.0-next.14) and then [extended bundling to Svelte libraries in dependencies](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-node%406.0.0-next.15). Netlify's adapter now [writes static files from the publish option rather than reading netlify.toml](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-netlify%407.0.0-next.12).

In kit itself, [query parameters beginning with x-sveltekit- are now rejected](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.28), which matters if you built anything custom against that reserved prefix. That release also [generates types when the dev server starts](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.28) and [supports bigint route params](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.28). Later prereleases fixed a [hashchange leaking to app listeners during focus handling](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.30), [kept a form.for instance registered across derived reconnects](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.30), [blurred focused SVG elements before navigation updates the DOM](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.29), and [made cookie options optional](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.29).

### EAS CLI adds Supabase and App Store Connect integrations

Expo's EAS CLI [added `eas integrations:supabase:advisors`](https://github.com/expo/eas-cli/releases/tag/v24.8.0), listing unresolved Supabase Security and Performance Advisor findings for the linked project, and now accepts [individual App Store Connect API keys](https://github.com/expo/eas-cli/releases/tag/v24.8.0) for submissions, TestFlight setup, and metadata — a real convenience for teams that would rather not hand over a shared key. The same release added `--build-fingerprint` to `eas simulator` and fixed a `Role: undefined` display bug for the Release Manager role.

## Releases covered

### Expo

- [EAS CLI v24.8.0 adds Supabase advisors and App Store Connect API key support](https://github.com/expo/eas-cli/releases/tag/v24.8.0)

### Svelte

- [@sveltejs/adapter-node@6.0.0-next.13](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-node%406.0.0-next.13)
- [@sveltejs/adapter-bun@1.0.0-next.3](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-bun%401.0.0-next.3)
- [@sveltejs/adapter-bun@1.0.0-next.5](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-bun%401.0.0-next.5)
- [@sveltejs/adapter-bun@1.0.0-next.4](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-bun%401.0.0-next.4)
- [@sveltejs/adapter-node@6.0.0-next.14](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-node%406.0.0-next.14)
- [@sveltejs/adapter-node@6.0.0-next.15](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-node%406.0.0-next.15)
- [@sveltejs/adapter-netlify@7.0.0-next.12](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/adapter-netlify%407.0.0-next.12)
- [@sveltejs/kit@3.0.0-next.28](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.28)
- [@sveltejs/kit@3.0.0-next.30](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.30)
- [@sveltejs/kit@3.0.0-next.29](https://github.com/sveltejs/kit/releases/tag/%40sveltejs/kit%403.0.0-next.29)

### Vercel

- [Next.js v16.3.6 patches remote code execution in next/og ImageResponse](https://github.com/vercel/next.js/releases/tag/v16.3.6)
- [Next.js v15.5.26 hardens next/og security](https://github.com/vercel/next.js/releases/tag/v15.5.26)
- [Next.js v16.4.0-canary.39 fixes prefetch loop and hardens next/og SVG serialization](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.39)
- [Next.js v16.4.0-canary.51 adds security upgrade insights to DevTools](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.51)
- [Next.js v16.4.0-canary.50 expands agentic upgrade support on prerelease channels](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.50)
- [Next.js v16.4.0-canary.41 preserves error boundaries in on-demand prerenders](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.41)
- [Next.js v16.4.0-canary.45 adds additionalRoots for Turbopack deployment adapters](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.45)
- [Next.js v16.4.0-canary.42 promotes next analyze command](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.42)
- [Next.js v16.4.0-canary.49 adjusts facade splitting and Turbopack loader roots](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.49)
- [Next.js v16.4.0-canary.43 tunes Node server chunking and fixes Turbopack module regression](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.43)
- [Next.js v16.4.0-canary.40 fixes Turbopack ModuleId regression](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.40)
- [Next.js v16.4.0-canary.48 fixes Server Actions hang and Edge SSR metadata streaming](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.48)
- [Next.js v16.4.0-canary.38 enables strict route matching by default](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.38)
- [Next.js v16.4.0-canary.46 reverts experimental custom webpack support](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.46)
- [Next.js v16.4.0-canary.47 prepares use cache for static root-param tracking](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.47)
- [Next.js v16.4.0-canary.44 defers turbo-tasks GC aggregation graph work](https://github.com/vercel/next.js/releases/tag/v16.4.0-canary.44)
