Back Cybersecuritynews Critical Vulnerability in Next-Mdx-Remote Allows Arbitrary Code Execution in React Server
Security advisory HCSEC-2026-01 revealed a critical vulnerability in the -mdx-remote library that allows attackers to execute arbitrary code on servers rendering untrusted MDX content. Tracked as CVE-2026-0969, the issue affects versions 4.3.0 through 5.0.0 and is fixed in 6.0.0. -mdx-remote is a popular open-source TypeScript library for .js based React apps. It lets developers pull […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
