🚨 Critical Next.js RCE: malicious AVIF/HEIC images can trigger unauthenticated remote code execution through the Image Optimization API.
The attack chain involves Next.js → sharp → libvips → libheif, with a critical heap buffer overflow tracked as GHSA-g89c-p67h-r497.
Also patched: CVE-2026-75604, a separate critical Windows-hosted Next.js RCE.
You must log in or # to comment.

