logo

next-mdx-remote Vulnerability Allows Arbitrary Code Execution in React SSR

ID: 4e2ded85-9ad7-5979-8282-3e46bb1b0152

STIX ID: report--4e2ded85-9ad7-5979-8282-3e46bb1b0152

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-02-13

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive summary:** A critical arbitrary code execution vulnerability (CVE-2026-0969) was discovered in next-mdx-remote (v4.3.0–5.0.0) allowing attackers to execute code on servers that compile untrusted MDX with JavaScript expressions enabled; upgrading to v6.0.0, which disables JS expressions by default and introduces blockDangerousJS protections, is strongly recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.