The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 12 Feb 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp shared Library |
|
| Vendors & Products |
Hashicorp
Hashicorp shared Library |
Thu, 12 Feb 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. | |
| Title | Arbitrary code execution in React server-side rendering of untrusted MDX content | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2026-02-12T01:35:06.231Z
Reserved: 2026-01-14T22:09:31.064Z
Link: CVE-2026-0969
No data.
Status : Received
Published: 2026-02-12T03:15:46.667
Modified: 2026-02-12T03:15:46.667
Link: CVE-2026-0969
No data.
OpenCVE Enrichment
Updated: 2026-02-12T09:02:06Z
Weaknesses