CVE-2026-0969: Hashicorp Shared Library

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-2026-0969, is fixed in next-mdx-remote 6.0.0.

Affected products

  • Hashicorp Shared Library: from 4.3.0, before 6.0.0 (fixed in 6.0.0)

Published 2026-02-12. Last modified 2026-06-17.