Turning on a faster image format gave Next.js sites an unauthenticated RCE — this one included
2026-08-31Security
Two critical flaws were patched in Next.js: a Windows path traversal at CVSS 9.0 and an AVIF heap buffer overflow at 9.5, both giving unauthenticated remote code execution. The AVIF one only fires if you enabled AVIF, which is a single line most people added for performance. Root Notes had that line.