A critical Next.js flaw could enable remote code execution through malicious SVG content during image generation.