criticalCVSS 9Vulnerability

CVE-2026-75604

## Impact A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem. ## Workaround There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.

Properties

severity
critical
summary
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
epss_score
0.01057
cvss_score
9
ghsa_published
2026-09-08T20:51:40Z
source_url
https://github.com/advisories/GHSA-p293-qw3h-jr36
ghsa_updated
2026-09-08T20:51:43Z
ghsa_id
GHSA-p293-qw3h-jr36
cve_id
CVE-2026-75604
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
is_ghsa_only
false
epss_percentile
0.62255

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/next

AFFECTS (1)

[Software]npm/next

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75604 (CVSS 9) — Ninja Signal Threat Intelligence | Ninja Signal