next is vulnerable to Remote Code Execution (RCE)
95
Critical Risk
The Image Optimization API processes AVIF input through sharp, which depends on libheif. A crafted AVIF can trigger a heap buffer overflow in libheif during decode/scale and execute arbitrary code in the Next.js process without authentication. Self-hosted deployments that optimize attacker-supplied or remotely fetched AVIF images are exposed. The fix disables AVIF optimization until a safe libheif/sharp stack is in place.
You are affected if you are using a version that falls within the vulnerable range and your deployment optimizes AVIF images through the Next.js Image Optimization API.
next is vulnerable to Remote Code Execution (RCE) in versions 10.0.0 - 15.5.23 and 16.0.0 - 16.3.2.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant