PoC public Vercel rce web-app
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
CVE Tools coverage
Vercel has shipped emergency patches for Next.js to address two critical vulnerabilities that permit unauthenticated remote code execution. One flaw, tracked as CVE-2026-75604, is a path traversal issue affecting applications using both the Pages and App Routers on Windows file systems, while the other stems from a heap buffer overflow in the libheif library when processing crafted AVIF images. The security fixes are available in versions 15.5.24 and 16.3.3, which were released ahead of schedule due to the severity of the issues; self-hosted users on Windows are urged to upgrade immediately as no workaround exists, whereas Vercel-hosted applications are already protected.