ID:13065 - Exploit for Path traversal in Next.js - CVE-2026-75604
Published: September 9, 2026
Next.js
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to path traversal in Pages and App router without Cache Component when handling requests on servers hosted on a Windows filesystem. A remote attacker can send a specially crafted request to execute arbitrary code.
Only applications using Pages and App router without Cache Component on Windows-hosted servers are vulnerable.