Netlify: Two critical Next.js vulnerabilities
The Next.js team disclosed two critical severity vulnerabilities that lead to unauthenticated remote code execution. Patched in 15.5.24 and 16.3.3.
Netlify confirmed its hosted sites are not affected by the Windows-specific issue, and do not run the affected image code path. Still, Netlify recommends upgrading to the patched releases as soon as possible.
Why a builder cares: RCE in a framework dependency is always urgent, but Netlify's explicit "you're not affected here" saves you from scrambling — just update your Next.js version and move on.