New deployments with vulnerable versions of the third-party package next-mdx-remote are now blocked by default
Any new deployment containing a version of next-mdx-remote that is vulnerable to CVE-2026-0969 will now automatically fail to deploy on Vercel.
Tom KnickmanSoftware Engineer