GHSA-p293-qw3h-jr36CriticalCVSS 9.0
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
🔗 CVE IDs covered (1)
📋 Description
Impact
A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.
Workaround
There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.
🎯 Affected products2
- npm/next:>= 13.4.0, < 15.5.24
- npm/next:>= 16.0.0, < 16.3.3
🔗 References (7)
- https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36
- https://nvd.nist.gov/vuln/detail/CVE-2026-75604
- https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b
- https://github.com/vercel/next.js/commit/b0f3460a92b955d3ca41fccff9a525a2b910fbf3
- https://github.com/vercel/next.js/releases/tag/v15.5.24
- https://github.com/vercel/next.js/releases/tag/v16.3.3
- https://github.com/advisories/GHSA-p293-qw3h-jr36