VDB
Sign up
HIGH8.8

GHSA-g4xw-jxrg-5f6m

next-mdx-remote affected by arbitrary code execution in React server-side rendering of untrusted MDX content

Quick fix

GHSA-g4xw-jxrg-5f6m — next-mdx-remote: upgrade to the fixed version with the command below.

npm install next-mdx-remote@6.0.0

Details

The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/next-mdx-remote
Introduced in: 4.3.0Fixed in: 6.0.0
Fixnpm install next-mdx-remote@6.0.0

References