New deployments with vulnerable versions of the third-party package next-mdx-remote are now blocked by default

next-mdx-remote CVE-2026-0969 Any new deployment containing a version of the third-party packagethat is vulnerable towill now automatically fail to deploy on Vercel. We strongly recommend upgrading to a patched version regardless of your hosting provider…

security

Sources

Vulnerabilities