CRITICALnpm →
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Affected packages
- next
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497
- https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4
- https://github.com/vercel/next.js/pull/97875
- https://github.com/vercel/next.js/pull/97931
- https://github.com/vercel/next.js/commit/3a15b4ac6ac8e70b1a9b18ecc18e8434462899b3
- https://github.com/vercel/next.js/commit/409772ec807def20132d251ad48fd8d8ad4c73c2
- https://github.com/vercel/next.js/commit/7a5937a8ab20b89d0a961f75eabb11577f5d5998
- https://github.com/vercel/next.js
- https://github.com/vercel/next.js/releases/tag/v15.5.24
- https://github.com/vercel/next.js/releases/tag/v16.3.3
Structured record: https://osv.dev/vulnerability/GHSA-2xp9-vwfh-vxw4
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→Vercel — Ship a patched app with zero-config deployment.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta