CRITICALCVSS 9.5
GHSA-2xp9-vwfh-vxw4
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Summary
A vulnerability in the underlying `libheif` library used by `sharp` which Next.js uses for image optimization can lead to remote code execution when AVIF files are optimized. Until a fix has propagated, optimization of AVIF files is disabled.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| npm | next | — | 15.5.24, 16.3.3 |
Remediation: Upgrade to 15.5.24 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.