Our takeVercel patches two critical Next.js flaws allowing unauthenticated RCE — one via crafted AVIF images (CVE pending detail), one a Windows path traversal (CVE-2026-75604). Update if you self-host; Vercel-hosted apps are already covered. Windows-filesystem servers are the priority.Cyber Resilience desk
Sources (3)
- hackernews · hackernews
- securityweek · securityweek
- securityweek · securityweek