Critical Next.js RCE: Malicious AVIF Images Expose Servers to Remote Code Execution

https://wp.me/pfPk8e-6ew

🚨 Critical Next.js RCE: malicious AVIF/HEIC images can trigger unauthenticated remote code execution through the Image Optimization API.

The attack chain involves Next.js → sharp → libvips → libheif, with a critical heap buffer overflow tracked as GHSA-g89c-p67h-r497.

Also patched: CVE-2026-75604, a separate critical Windows-hosted Next.js RCE.

17 points · 0 comments · view on lemmy.world

0 Comments

No comments yet.