New deployments with vulnerable versions of the third-party package next-mdx-remote are now blocked by default
next-mdx-remote CVE-2026-0969 Any new deployment containing a version of the third-party packagethat is vulnerable towill now automatically fail to deploy on Vercel. We strongly recommend upgrading to a patched version regardless of your hosting provider…
Sources
- T1New deployments with vulnerable versions of the third-party package next-mdx-remote are now blocked by defaultVercel (blog + changelog)