Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
Impact
A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.
Workaround
There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.
Weakness classes: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Source: GHSA-p293-qw3h-jr36 · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page