logo

Critical Vulnerability in Next-Mdx-Remote Allows Arbitrary Code Execution in React Server-Side Rendering

ID: c943219f-fb45-5244-8a11-f9579fee83f1

STIX ID: report--c943219f-fb45-5244-8a11-f9579fee83f1

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-02-13

Date Updated: 2026-04-21

Author: Abinaya

...
...

Security advisory HCSEC-2026-01 discloses CVE-2026-0969, a critical RCE in next-mdx-remote (v4.3.0–5.0.0) where untrusted MDX containing JavaScript expressions can be evaluated during server-side rendering, allowing attackers to execute eval/require/Function and potentially take over servers; upgrade to next-mdx-remote 6.0.0 (which blocks JS expressions by default), audit uses of compileMDX/serialize, sanitize user-supplied MDX, and test changes in staging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.