Skip to main content
CyberConfirmedMediumDeveloping
6.6

Next.js patches two critical remote code execution vulnerabilities

Next.js has released security updates addressing two critical vulnerabilities that could allow unauthenticated remote code execution. One flaw specifically impacts Windows-hosted environments, while the other is triggered via AVIF image optimization. No active exploitation has been observed to date.

The Hacker News1 day agoengCredibility 61%View source

Score Breakdown

Mosaic Score6.6
Confidence0.9
Significance0.5
Source credibility0.6
Source

Related signals

8 found