A critical path traversal vulnerability in Next.js (CVSS 9.0) affects applications using Pages Router or App Router without Cache Components on Windows filesystems. It allows unauthenticated remote code execution. Patches are available in Next.js 15.5.24 and 16.3.3.