New deployments containing vulnerable versions of the next-mdx-remote package are now blocked by default
Key point
Vercel automatically blocks new deployments that include the next-mdx-remote package affected by the CVE-2026-0969 vulnerability.
Details
Vercel automatically blocks all new deployments that include specific versions of the third-party package next-mdx-remote, in which the CVE-2026-0969 vulnerability was discovered.
Users are strongly encouraged to update to a patched version regardless of their hosting environment.
If you need to disable this automatic protection, you can bypass it by setting DANGEROUSLY_DEPLOY_VULNERABLE_CVE_2026_0969=1 in your Vercel project's environment variables.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.