GHSA-2xp9-vwfh-vxw4
A vulnerability in the underlying libheif library used by sharp which Next.js uses for image optimization can lead to remote code execution when AVIF files are optimized.
Until a fix has propagated, optimization of AVIF files is disabled.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497, https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4, https://github.com/vercel/next.js/pull/97875, https://github.com/vercel/next.js/pull/97931, https://github.com/vercel/next.js/commit/3a15b4ac6ac8e70b1a9b18ecc18e8434462899b3, https://github.com/vercel/next.js/commit/409772ec807def20132d251ad48fd8d8ad4c73c2, https://github.com/vercel/next.js/commit/7a5937a8ab20b89d0a961f75eabb11577f5d5998, https://github.com/vercel/next.js, https://github.com/vercel/next.js/releases/tag/v15.5.24, https://github.com/vercel/next.js/releases/tag/v16.3.3