CVE-2026-0969

T

he serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-2026-0969, is fixed in next-mdx-remote 6.0.0.

Configurations

No configuration.

History

12 Feb 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 03:15

Updated : 2026-02-12 15:16


NVD link : CVE-2026-0969

Mitre link : CVE-2026-0969

CVE.ORG link : CVE-2026-0969


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')