HashiCorp disclosed HCSEC-2026-01 (tracked as CVE-2026-0969 / GHSA-g4xw-jxrg-5f6m) affecting the next-mdx-remote library used by Next.js applications to render MDX content. The flaw can lead to arbitrary code execution when applications server-side render untrusted MDX due to insufficient sanitization in the serialize compilation path, particularly when JavaScript expressions in MDX are permitted; the issue is categorized as CWE-94 (code injection) and reported with a CVSS 3.1 score of 8.8 (High).
Guidance from the Canadian Centre for Cyber Security and third-party analysis both recommend updating affected deployments. Impacted versions are reported as 4.3.0 through 5.0.0 (Cyber Centre advisory) and 4.3.0 up to but not including 6.0.0 (Socket), with remediation available in 6.0.0; the 6.0.0 release also changes defaults to reduce exposure by disabling JavaScript expressions by default (blockJS: true) and adding additional guardrails when dangerous JS is explicitly enabled (e.g., best-effort blocking of constructs like eval, Function, process, and require).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-12, the Canadian Centre for Cyber Security published alert AV26-123 referencing HashiCorp's advisory and urging users and administrators to review the guidance and apply necessary updates. The notice highlighted the arbitrary code execution risk in affected next-mdx-remote versions.
HashiCorp reported the vulnerability is fixed in next-mdx-remote 6.0.0. The release changes defaults to disable JavaScript expressions by default and adds additional protections when expressions are explicitly enabled.
On 2026-02-11, HashiCorp published advisory HCSEC-2026-01 describing a high-severity arbitrary code execution vulnerability in next-mdx-remote when untrusted MDX is server-side rendered. The issue affects versions starting at 4.3.0 and was assigned CVE-2026-0969 / GHSA-g4xw-jxrg-5f6m.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecyber.gc.ca
Open sourcediscuss.hashicorp.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.