next-mdx-remote Vulnerability Allows Arbitrary Code Execution in React SSR
ID: 4e2ded85-9ad7-5979-8282-3e46bb1b0152
STIX ID: report--4e2ded85-9ad7-5979-8282-3e46bb1b0152
Feed Name: GBHackers
Threat Score
**Executive summary:** A critical arbitrary code execution vulnerability (CVE-2026-0969) was discovered in next-mdx-remote (v4.3.0–5.0.0) allowing attackers to execute code on servers that compile untrusted MDX with JavaScript expressions enabled; upgrading to v6.0.0, which disables JS expressions by default and introduces blockDangerousJS protections, is strongly recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
