CVE-2026-75604
Description
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/next/src/server/lib/incremental-cache/file-system-cache.ts, a remote request can supply encoded Windows path separators that traverse outside the intended cache root and expose private build data, including the server-reference-manifest encryption key. Disclosure of that key can enable remote code execution in the affected application. This issue is fixed in versions 15.5.24 and 16.3.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nextnpm | >= 13.4.0, < 15.5.24 | 15.5.24 |
nextnpm | >= 16.0.0, < 16.3.3 | 16.3.3 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-p293-qw3h-jr36ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-75604ghsaADVISORY
- github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51bnvdWEB
- github.com/vercel/next.js/commit/b0f3460a92b955d3ca41fccff9a525a2b910fbf3nvdWEB
- github.com/vercel/next.js/releases/tag/v15.5.24nvdWEB
- github.com/vercel/next.js/releases/tag/v16.3.3nvdWEB
- github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36nvdWEB
News mentions
5- Metasploit Wrap Up: This One Goes to Sixteen!Rapid7 Blog · Sep 11, 2026
- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and MoreThe Hacker News · Aug 31, 2026
- 31st August – Threat Intelligence ReportCheck Point Research · Aug 31, 2026
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCEThe Hacker News · Aug 27, 2026
- Critical Next.js Vulnerabilities Enables Remote Code Execution AttacksCyber Security News · Aug 26, 2026