Nextjs Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Credit Hacktron Vercel has released security patches for two criticalseverity vulnerabilities in the Nextjs web framework both of which allow unauthenticated remote code execution one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem The Windows path traversal tracked as CVE202675604