Post
CRITICAL

Next.js Patches Critical AVIF and Windows Path Traversal Flaws Enabling Unauthenticated RCE

· rce · vulnerability · cve

Vercel has released patches for two critical-severity vulnerabilities in the Next.js web framework, both allowing unauthenticated remote code execution. One is exploitable via specially crafted AVIF image files; the other is a path traversal flaw, tracked as CVE-2026-75604, affecting servers that run on a Windows filesystem.

Teams running Next.js in production, particularly on Windows hosts, should update immediately. No confirmation of in-the-wild exploitation was included in the source summary.