Critical RCE Vulnerability in -mdx-remote Library Affects React Servers

Critical RCE Vulnerability in -mdx-remote Library Affects React Servers

First seen 13 Feb 2026, 07:08 UTC Discuss.HashicorpCybersecuritynewsDev.To 78% similarity 68.3

Article Content

Browse articles
ThreatCluster

A critical vulnerability tracked as CVE-2026-0969 was disclosed in the -mdx-remote library, allowing attackers to execute arbitrary code on servers that render untrusted MDX content. The vulnerability affects versions 4.3.0 through 5.0.0 and has been addressed in version 6.0.0, which introduces a breaking change to mitigate the risk.

ThreatCluster AI

Timeline

2026-02-12
CVE-2026-0969 published
2026-02-13
Security advisory HCSEC-2026-01 released

Community

Browse all →