Skip to content
Critical Vulnerability in Next-Mdx-Remote Allows Arbitrary Code Execution in React Server

Critical Vulnerability in Next-Mdx-Remote Allows Arbitrary Code Execution in React Server

Cybersecuritynews Abinaya February 13, 2026

Security advisory HCSEC-2026-01 revealed a critical vulnerability in the -mdx-remote library that allows attackers to execute arbitrary code on servers rendering untrusted MDX content. Tracked as CVE-2026-0969, the issue affects versions 4.3.0 through 5.0.0 and is fixed in 6.0.0. -mdx-remote is a popular open-source TypeScript library for .js based React apps. It lets developers pull […]

Extracted Entities

Attack Types (1)

CVEs (1)

Platforms (2)