New deployments of vulnerable Next.js applications are now blocked by default
CVE-2025-66478 Any new deployment containing a version of Next.js that is vulnerable towill now automatically fail to deploy on Vercel. Learn more We strongly recommend upgrading to a patched version regardless of your hosting provider. DANGEROUSLY_DEPLOY_VULNERABLE_CVE_2025_66478=1 Learn more This…
Sources
- T1New deployments of vulnerable Next.js applications are now blocked by defaultVercel (blog + changelog)