Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
GHSA-2xp9-vwfh-vxw4 — CVSS 0/10. Fix: upgrade to 15.5.24.
A vulnerability in the underlying `libheif` library used by `sharp` which Next.js uses for image optimization can lead to remote code execution when AVIF files are optimized.
Until a fix has propagated, optimization of AVIF files is disabled.
Weakness classes: CWE-1395 (Dependency on Vulnerable Third-Party Component)
Source: GHSA-2xp9-vwfh-vxw4 · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page