next is vulnerable to Remote Code Execution (RCE)
90
Critical Risk
On Windows-hosted deployments, Pages and App Router request handling without Cache Components can resolve attacker-controlled path input in a way that escapes the intended application root. An unauthenticated request can therefore reach filesystem locations outside the app and achieve remote code execution on the server. The fix hardens path resolution so Windows filesystem semantics cannot turn request paths into out-of-root execution.
You are affected if you are using a version that falls within the vulnerable range and your Next.js server runs on a Windows filesystem with Pages or App Router without Cache Components.
next is vulnerable to Remote Code Execution (RCE) in versions 13.4.0 - 15.5.23 and 16.0.0 - 16.3.2.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant