GHSA-p293-qw3h-jr36CriticalCVSS 9.0

Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

Published
September 8, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.

Workaround

There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.

🎯 Affected products2

  • npm/next:>= 13.4.0, < 15.5.24
  • npm/next:>= 16.0.0, < 16.3.3

🔗 References (7)