New deployments with vulnerable versions of the third-party package next-mdx-remote are now blocked by default
Any new deployment containing a version of the third-party package that is vulnerable to will now automatically fail to deploy on Vercel.next-mdx-remoteCVE-2026-0969 We strongly recommend upgrading to a patched version regardless of your hosting provider. This automatic protection can be disabled by setting the environment variable on your Vercel project. DANGEROUSLY_DEPLOY_VULNERABLE_CVE_2026_0969=1Learn more Read more
