CVE-2026-0969Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-2026-0969, is fixed in next-mdx-remote 6.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 11 signals
  • Disclosure: 7 classified signals
  • Peaked 3d ago at 6 mentions (2026-02-12); latest day: 1
  • 12 total mentions across 4 days

Deep dive

Activity timeline12 mentions / 4d
02356Mentions · 2026-02-12: 6Mentions · 2026-02-13: 4Mentions · 2026-02-14: 1Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-12: 3Patch / Workaround · 2026-02-13: 3Patch / Workaround · 2026-02-14: 1Technical Details · 2026-02-12: 6Technical Details · 2026-02-13: 3Technical Details · 2026-02-14: 1Technical Details · 2026-02-20: 102-1202-1302-1402-20
Signal classification2 categories
Disclosure
758.3%
Patch
541.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-126
Disclosure4Patch2
2026-02-134
Disclosure2Patch2
2026-02-141
Patch1
2026-02-201
Disclosure1
Full discourse12 posts
  • Socket@SocketSecurity
    Patch

    Update: We’ve published free Socket Certified Patches for the next-mdx-remote RCE vulnerability (CVE-2026-0969). No dependency upgrade required, and you don’t have to be a Socket customer to use them. Details: https://socket.dev/blog/high-severity-rce-vulnerability-disclosed-in-next-mdx-remote #NextJS

    Post summary

    Socket released free patches for the high‑severity RCE (CVE-2026-0969) in next-mdx-remote, with no dependency upgrade required.

    151832.3K
    5.3K followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Disclosure

    🚨 ALERTĂ: Vulnerabilitate critică în biblioteca next-mdx-remote (React/Next.js) - CVE-2026-0969 🔎 A fost identificată o vulnerabilitate de severitate ridicată care afectează biblioteca next-mdx-remote. 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitate-severa-in-biblioteca-next-mdx-remote-react-next-js #DNSC #CVE https://t.co/QyFigPErpB

    Post summary

    The tweet announces a high‑severity vulnerability (CVE‑2026‑0969) affecting the next‑mdx‑remote library, but provides no technical specifics, PoC, exploit code, or patch information.

    11050140
    4.6K followersView on X
  • Rafter@RafterSecurity
    Patch

    CVE-2026-0969: Remote code execution in next-mdx-remote v4.3.0–5.0.0. Server-side rendering of untrusted MDX content can lead to arbitrary code execution. If you're using next-mdx-remote in a Next.js app—especially for blog posts or user content—upgrade to v6.0.0 now. This is a real RCE, not a theoretical risk. Patch today.

    Post summary

    The post highlights a confirmed remote code execution vulnerability in next‑mdx‑remote and urges users to upgrade to v6.0.0 immediately to apply the available patch.

    2001081
    11 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical next-mdx-remote RCE (CVE-2026-0969) lets untrusted MDX pop your Next.js server A flaw in next-mdx-remote’s serialize/compileMDX path allows arbitrary code execution when server-side rendering untrusted MDX (JS expressions inside {} can execute with server privileges), fixed in v6.0.0 with JS-blocking defaults. If you render user-supplied MDX, upgrade immediately and audit all SSR MDX ingestion paths. 🎯 Target: Global/Developers (Next.js/React SSR) #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cybersecuritynews.com/vulnerability-in-next-mdx-remote/

    Post summary

    CVE-2026-0969 enables arbitrary code execution in next-mdx-remote when rendering untrusted MDX; the vulnerability is fixed in v6.0.0 with JS-blocking defaults, so users should upgrade immediately.

    01110119
    191 followersView on X
  • Feross@feross
    Disclosure

    1/ 🚨 High-severity RCE disclosed in next-mdx-remote. HashiCorp just published HCSEC-2026-01 for CVE-2026-0969 (CVSS 8.8). If you compile untrusted MDX on the server, this can lead to arbitrary code execution.

    Post summary

    HashiCorp has disclosed a high‑severity RCE (CVE‑2026‑0969) in next‑mdx‑remote, noting that compiling untrusted MDX can lead to arbitrary code execution, but no PoC, exploit code, or patch details are provided.

    20010776
    29.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High code injection in #MDX #Hashicorp. CVE-2026-0969 CVSS: 8.8. A remote attacker with low privileges can compromise the CIA of the system. Upgrade to next-mdx-remote 6.0.0 or later. #Patch #Patch #Patch

    Post summary

    CVE-2026-0969 is a high‑severity code injection flaw affecting MDX/Hashicorp; users should upgrade to next-mdx-remote 6.0.0 or later to mitigate the risk.

    10001254
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0969 Arbitrary Code Execution in Next MDX Remote via Unsanitized Serialize Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0969

    Post summary

    The post announces CVE-2026-0969, detailing an arbitrary code execution vulnerability in Next MDX caused by an unsanitized serialization function.

    0002060
    4.0K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Next-Mdx-Remote の深刻な脆弱性 CVE-2026-0969 が FIX:React Server での任意のコード実行 https://iototsecnews.jp/2026/02/13/critical-vulnerability-in-next-mdx-remote-allows-arbitrary-code-execution-in-react-server-side-rendering/ React アプリで Markdown と JSX を組み合わせて表示する際に便利な next-mdx-remote ライブラリに、サーバの完全な乗っ取りにいたる深刻な脆弱性が発見されました。この問題の原因は、MDX 内の波括弧 “{ }”で囲まれた JavaScript 式を処理する際の、サーバ側での不十分なサニタイズに起因します。通常、Markdown は静的なテキストとして扱われますが、MDX はプログラム (JavaScript) を実行できるという特性を持っています。そのため、攻撃者が “OS コマンドを実行せよ” といった悪意の命令を MDX に紛れ込ませると、サーバ上で正規のプログラムとして実行され、リモートコード実行 (RCE) を引き起こすという不備が生じています。ご利用のチームは、ご注意ください。 #CVE20260969 #NextMdxRemote #React #Vulnerability

    Post summary

    The article announces a critical RCE vulnerability (CVE-2026-0969) in next‑mdx‑remote, detailing the flaw but providing no PoC, exploit code, or evidence of active exploitation.

    01000153
    484 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0969 The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. https://www.cve.org/CVERecord?id=CVE-2026-0969

    Post summary

    The post announces a new vulnerability (CVE-2026-0969) in next-mdx-remote’s serialize function, enabling arbitrary code execution by failing to properly sanitize MDX content.

    00001148
    56.5K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical next-mdx-remote RCE (CVE-2026-0969) lets untrusted MDX pop your Next.js server A critical flaw in next-mdx-remote (v4.3.0–v5.0.0) allows arbitrary code execution when server-side rendering untrusted MDX with JavaScript expressions enabled, enabling full server compromise in SSR pipelines. Upgrade to v6.0.0 (JS-blocking defaults) and audit any user-supplied MDX ingestion paths. 🎯 Target: Global/Developers (Next.js/React SSR) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/vulnerability-in-next-mdx-remote-enables/

    Post summary

    CVE‑2026‑0969 is a critical RCE in next‑mdx‑remote; users should immediately upgrade to v6.0.0 and review any user‑supplied MDX ingestion paths.

    0000040
    191 followersView on X
  • 趣テクノロジー@omomuki_tech
    Disclosure

    Next.jsで人気のライブラリ「next-mdx-remote」に、任意のコードが実行されてしまう重大な脆弱性(CVE-2026-0969)が発見されました。 この問題は、信頼できないMDXコンテンツをReactでサーバーサイドレンダリングする際に発生する可能性があります。攻撃者によってサーバー上で任意のコードが実行される恐れがあるため、非常に危険度の高い脆弱性です。 影響を受けるのはバージョン4.3.0から5.0.0までとなります。この脆弱性はバージョン6.0.0で修正済みですので、該当するバージョンを利用している開発者の方は、速やかにアップデートすることが強く推奨されます。 #脆弱性 #Nextjs #React https://cybersecuritynews.com/vulnerability-in-next-mdx-remote/

    Post summary

    CVE‑2026‑0969 allows arbitrary code execution on servers when next‑mdx‑remote renders untrusted MDX content; affected versions 4.3.0–5.0.0 are fixed in 6.0.0 and users should update immediately.

    0000048
    240 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-0969: HIGH] Vulnerability in next-mdx-remote allows arbitrary code execution due to lack of MDX content sanitization. CVE-2026-0969 fixed in version 6.0.0. #cybersecurity#cve,CVE-2026-0969,#cybersecurity https://cvefind.com/CVE-2026-0969

    Post summary

    The post announces CVE‑2026‑0969 in next-mdx‑remote, noting it allows arbitrary code execution, and mentions that version 6.0.0 contains a fix.

    0000047
    583 followersView on X

Explore more