ZÉROJOUR

The zero-day paper — printed from structured content, not scraped prose.
Permanent editionPublic dataset · Sanity GROQGHSA × CISA KEV
next (npm) · published 2026-09-08

Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

CVE-2026-75604 — CVSS 9/10. Fix: upgrade to 15.5.24.
Package
next
Ecosystem
npm
Vector
NETWORK
Complexity
HIGH
Privileges
NONE
Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Impact

A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.

Workaround

There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.

Weakness classes: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Source: GHSA-p293-qw3h-jr36 · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page

ZéroJour prints itself from a Sanity dataset of real advisories (GitHub Advisory Database, CC-BY-4.0; CISA KEV). No scraping, no keyword search — headlines are typed fields, scores are numbers, fixes are versions. The newsroom composes, a human approves.