A path traversal flaw in Next.js lets an unauthenticated attacker redirect a cache write outside its directory on Windows-hosted servers, reaching remote code execution on the host.
Read more about Emerging Threat: (CVE-2026-75604) Next.js Remote Code Execution via Windows Path Traversal