Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Read full story on The Hacker News
Share
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
AI disclosure

Summary

Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.