A AegiFlow
CRITICALCVSS 9.5

GHSA-2xp9-vwfh-vxw4

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

Published
2026-09-08
Modified
2026-09-08
Sources
github-advisory

Summary

A vulnerability in the underlying `libheif` library used by `sharp` which Next.js uses for image optimization can lead to remote code execution when AVIF files are optimized. Until a fix has propagated, optimization of AVIF files is disabled.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmnext15.5.24, 16.3.3

Remediation: Upgrade to 15.5.24 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.