UUDoIt
CyberSecurity

Critical Next.js RCE Flaws: What Teams Running Next.js Must Do

Vercel patched two critical unauthenticated RCE flaws in Next.js โ€” a Windows path traversal (CVSS 9.0) and an AVIF image bug. Here's who's affected and how to fix it.

The UDoIt Desk3 min read
Critical Next.js RCE Flaws: What Teams Running Next.js Must Do
Photo: Pixabay / Pexels

Vercel has patched two critical, unauthenticated remote-code-execution (RCE) vulnerabilities in Next.js โ€” the framework behind a huge slice of the modern web (tens of millions of weekly downloads). Both let an attacker run code on a vulnerable server without logging in. If your team self-hosts a Next.js app, this is a drop-everything-and-patch situation.

Fixed versions: Next.js 15.5.24 (Maintenance LTS) and 16.3.3 (Active LTS), published August 25, 2026. Apps hosted on Vercel are protected at the platform level โ€” but self-hosted deployments need to act.

Flaw 1 โ€” Windows path traversal (CVE-2026-75604, CVSS 9.0)

A path-traversal vulnerability affecting Next.js apps that run on a Windows filesystem (using the Pages Router and App Router without Cache Components). An unauthenticated attacker can traverse the filesystem to reach and execute code.

  • Affected: Windows-hosted servers only
  • Not affected: Linux and macOS deployments
  • Fix: upgrade to a patched release โ€” there is no known workaround for affected Windows hosts

Flaw 2 โ€” AVIF image RCE (GHSA-2xp9-vwfh-vxw4)

The nastier one for most teams. It originates in the upstream libheif dependency and triggers when Next.js Image Optimization processes a maliciously crafted AVIF file. Feed the optimizer a bad image and you get unauthenticated RCE.

  • Affected: Next.js 10.0.0 up to (but not including) 15.5.24, and releases before 16.3.3
  • Trigger: Image Optimization enabled and processing attacker-supplied AVIF input
  • Risk multiplier: apps that optimize remote images from arbitrary hosts โ€” an attacker can point the /_next/image endpoint at a crafted AVIF

Who needs to do what

๐Ÿ‘ Pros

  • โœ“On Vercel? You're protected โ€” Vercel patched it at the platform level
  • โœ“On Linux/macOS self-host? The Windows flaw doesn't apply (but the AVIF one still might)

๐Ÿ‘Ž Cons

  • โœ•Self-hosting on Windows? Critical โ€” upgrade now, no workaround
  • โœ•Optimizing untrusted remote images? Exposed to the AVIF RCE until you patch

Remediation checklist

  1. Upgrade Next.js to 15.5.24 or 16.3.3. This closes both holes. (If you're on the 14.x line, note the fix ships in 15/16 โ€” plan the major upgrade, or apply the mitigations below in the meantime.)
  2. Lock down image optimization. In next.config, restrict images.remotePatterns to only the hosts you actually serve images from, instead of a wildcard โ€” this shrinks the AVIF attack surface dramatically.
  3. If you can't patch immediately and you self-host on Windows, treat the box as high-risk: put it behind a WAF, and prioritize the upgrade.
  4. Confirm your host. If you deploy on Vercel, verify in their August 2026 security notice โ€” you're covered โ€” but still upgrade your dependency to stay off the affected line.

The takeaway

Two unauthenticated RCEs at CVSS 9.0+ in a framework this widely used is about as serious as web-app security gets. Vercel-hosted apps are covered; self-hosted apps โ€” especially on Windows or optimizing untrusted images โ€” should patch today. Upgrade to 15.5.24 / 16.3.3, tighten remotePatterns, and move on with your day.

See also our coverage of the industry warning on AI-driven cyberattacks. Details from published advisories; verify specifics against the official Next.js/Vercel security release for your version.

The AI stack, in your inbox

One email a week: the tools worth trying, the automations worth stealing. Join the teams building smarter with UDoIt.

Keep reading