[CIVN-2026-0433] Remote Code Execution Vulnerability in Next.js

By Published On: September 3, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Remote Code Execution Vulnerability in Next.js


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Next.js version 13.4 or higher and prior to 15.5.24

Next.js version 16.0 or higher and prior to 16.3.3

Overview


A critical vulnerability has been reported in Next.js, which may allow an unauthenticated remote attacker to execute arbitrary code on a targeted windows hosted system under specific application and runtime conditions.


Target Audience:

Organizations developing or hosting web applications using the Next.js framework.


Risk Assessment:

Risk of unauthorized remote code execution and system compromise


Impact Assessment:

Unauthorized access to sensitive data, data manipulation, and complete system compromise.


Description


Next.js is an open source React framework developed by Vercel for building full-stack web applications with features like server-side rendering, static site generation, API routes, and optimized performance.


This vulnerability exists in Next.js due to improper limitation of a pathname to a restricted directory (Path Traversal). Under specific application configurations, an unauthenticated remote attacker may exploit path traversal to access or manipulate files outside the intended cache directory. The vulnerability specifically affects applications using both the Pages Router and App Router without Cache Components when the application is hosted on a Windows file system.


Successful exploitation may allow an unauthenticated remote attacker to execute arbitrary code on a targeted windows hosted system under specific application and runtime conditions.


Solution


Apply appropriate updates as mentioned in:

https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36



Vendor Information


Next.js

https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36


References


Next.js

https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36


CVE Name

CVE-2026-75604




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqZiB0ACgkQ3jCgcSdc

ys8pLhAAgwX4M9J3eNEeU8MSc7/vl2w/o/5QzT2A3gGL3jBMAHjyqGw0S9NNLTgu

wsVOA+58kfEg8IZMb5azg64HImEm+8IB74kFmN5Zlzj0r+gVCVLdGT5PT8BiwH21

kxnl/qsv2+OJgdt6RP9PrZeWiIpYoLTrsNUOfoWmftFMLlv3+TQZXGPVPs2Jt/gn

2AeLV8MIpKzQnWSHLYs6FNK1H8gYyKHXRmDcVs/22Yan/jtJRP9PEgsxwSnbKuye

bA8hN2bsNoDcLtXbkPZmk/VuFREWnDjnv2awR8soKx7ZfhgRJWNcn+F0MTbnDi4o

jzl8em6F9DmBeNjNrUnv74BYuu3UVwInXLIBOUMkkR3aRFl7gU5SjPXe++WwCbFw

UHHETaHTFqcgga2P0wHiLVl0OCgA+ja3nVDftbxIHAHzawp+NUYZEaSy3StR7x1R

pHmQlzT858vMu0n0SXM/ExQO5/zsDgzv887Cnjf02lxv+Oj5d0Zo4gfPwKHfC1tI

HUqhoNb7zDTy4aNWzI1E3SChfr+EYXvntXgBLlHV3VliG8P2a/5HZSAn7Nhnp7b3

wDP7YmKf1vXgj9z5EwhB3v1/7kdSTj+NMuxWuQRuev/T9th2+Pz+u5ucRxNdmyli

k3A2CXLVfrjLO+l1CsTKWlQbZ5p7CeRTgKjghX4BYEujp8E0de0=

=xpXE

—–END PGP SIGNATURE—–

Share this article