criticalCVSS 9Vulnerability
CVE-2026-75604
## Impact A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem. ## Workaround There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.
Properties
- severity
- critical
- summary
- Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
- epss_score
- 0.01057
- cvss_score
- 9
- ghsa_published
- 2026-09-08T20:51:40Z
- source_url
- https://github.com/advisories/GHSA-p293-qw3h-jr36
- ghsa_updated
- 2026-09-08T20:51:43Z
- ghsa_id
- GHSA-p293-qw3h-jr36
- cve_id
- CVE-2026-75604
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- is_ghsa_only
- false
- epss_percentile
- 0.62255
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]npm/next
AFFECTS (1)
→[Software]npm/next
HAS_WEAKNESS (1)
→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Explore deeper with Ninja Signal's threat intelligence graph