
[CIVN-2026-0433] Remote Code Execution Vulnerability in Next.js
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Remote Code Execution Vulnerability in Next.js
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Next.js version 13.4 or higher and prior to 15.5.24
Next.js version 16.0 or higher and prior to 16.3.3
Overview
A critical vulnerability has been reported in Next.js, which may allow an unauthenticated remote attacker to execute arbitrary code on a targeted windows hosted system under specific application and runtime conditions.
Target Audience:
Organizations developing or hosting web applications using the Next.js framework.
Risk Assessment:
Risk of unauthorized remote code execution and system compromise
Impact Assessment:
Unauthorized access to sensitive data, data manipulation, and complete system compromise.
Description
Next.js is an open source React framework developed by Vercel for building full-stack web applications with features like server-side rendering, static site generation, API routes, and optimized performance.
This vulnerability exists in Next.js due to improper limitation of a pathname to a restricted directory (Path Traversal). Under specific application configurations, an unauthenticated remote attacker may exploit path traversal to access or manipulate files outside the intended cache directory. The vulnerability specifically affects applications using both the Pages Router and App Router without Cache Components when the application is hosted on a Windows file system.
Successful exploitation may allow an unauthenticated remote attacker to execute arbitrary code on a targeted windows hosted system under specific application and runtime conditions.
Solution
Apply appropriate updates as mentioned in:
https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36
Vendor Information
Next.js
https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36
References
Next.js
https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36
CVE Name
CVE-2026-75604
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqZiB0ACgkQ3jCgcSdc
ys8pLhAAgwX4M9J3eNEeU8MSc7/vl2w/o/5QzT2A3gGL3jBMAHjyqGw0S9NNLTgu
wsVOA+58kfEg8IZMb5azg64HImEm+8IB74kFmN5Zlzj0r+gVCVLdGT5PT8BiwH21
kxnl/qsv2+OJgdt6RP9PrZeWiIpYoLTrsNUOfoWmftFMLlv3+TQZXGPVPs2Jt/gn
2AeLV8MIpKzQnWSHLYs6FNK1H8gYyKHXRmDcVs/22Yan/jtJRP9PEgsxwSnbKuye
bA8hN2bsNoDcLtXbkPZmk/VuFREWnDjnv2awR8soKx7ZfhgRJWNcn+F0MTbnDi4o
jzl8em6F9DmBeNjNrUnv74BYuu3UVwInXLIBOUMkkR3aRFl7gU5SjPXe++WwCbFw
UHHETaHTFqcgga2P0wHiLVl0OCgA+ja3nVDftbxIHAHzawp+NUYZEaSy3StR7x1R
pHmQlzT858vMu0n0SXM/ExQO5/zsDgzv887Cnjf02lxv+Oj5d0Zo4gfPwKHfC1tI
HUqhoNb7zDTy4aNWzI1E3SChfr+EYXvntXgBLlHV3VliG8P2a/5HZSAn7Nhnp7b3
wDP7YmKf1vXgj9z5EwhB3v1/7kdSTj+NMuxWuQRuev/T9th2+Pz+u5ucRxNdmyli
k3A2CXLVfrjLO+l1CsTKWlQbZ5p7CeRTgKjghX4BYEujp8E0de0=
=xpXE
—–END PGP SIGNATURE—–


