{"id":"GHSA-p293-qw3h-jr36","summary":"Next.js: Unauthenticated Remote Code Execution on windows-hosted servers","details":"## Impact\n\nA vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.\n\n## Workaround\n\nThere is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.","aliases":["CVE-2026-75604"],"modified":"2026-09-08T21:00:06.133833950Z","published":"2026-09-08T20:51:40Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-09-08T20:51:40Z","nvd_published_at":"2026-09-01T22:17:12Z","cwe_ids":["CWE-22"]},"references":[{"type":"WEB","url":"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75604"},{"type":"WEB","url":"https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b"},{"type":"WEB","url":"https://github.com/vercel/next.js/commit/b0f3460a92b955d3ca41fccff9a525a2b910fbf3"},{"type":"PACKAGE","url":"https://github.com/vercel/next.js"},{"type":"WEB","url":"https://github.com/vercel/next.js/releases/tag/v15.5.24"},{"type":"WEB","url":"https://github.com/vercel/next.js/releases/tag/v16.3.3"}],"affected":[{"package":{"name":"next","ecosystem":"npm","purl":"pkg:npm/next"},"ranges":[{"type":"SEMVER","events":[{"introduced":"13.4.0"},{"fixed":"15.5.24"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-p293-qw3h-jr36/GHSA-p293-qw3h-jr36.json"}},{"package":{"name":"next","ecosystem":"npm","purl":"pkg:npm/next"},"ranges":[{"type":"SEMVER","events":[{"introduced":"16.0.0"},{"fixed":"16.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-p293-qw3h-jr36/GHSA-p293-qw3h-jr36.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}