importantSYS.SOURCE: The Hacker News• 2026-08-27T20:43:00+05:30
Next.js Addresses Critical AVIF and Windows Vulnerabilities Allowing Unauthenticated RCE
Next.js has released security patches for two critical vulnerabilities, one exploiting AVIF image processing and another a Windows path traversal flaw, both enabling unauthenticated remote code execution (RCE). The fixes are available in Next.js 15.5.24 and 16.3.3, affecting versions up to 15.5.23 and 16.3.2.
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem.
The Windows path traversal, tracked as CVE-2026-75604&
*** END OF TRANSMISSION ***