NPM · JUNE 2026 · CONFIRMED

remotion npm Package Arbitrary File Write Vulnerability Confirmed

GHSA-G6PC-6676-C23JSeverity: HIGH

The remotion npm package version v4.0.409 has been confirmed to contain an arbitrary file write vulnerability by multiple independent sources. Users of this specific version are affected.

What happened

The remotion npm package version v4.0.409 was discovered to have an arbitrary file write vulnerability, tracked as GHSA-g6pc-6676-c23j and CVE-2026-30121. This vulnerability allows an attacker to write arbitrary files to the filesystem, potentially leading to unauthorized access or code execution. The vulnerability was confirmed by multiple independent sources.

To assess your exposure, check if your projects or dependencies are using remotion version v4.0.409. If so, you are vulnerable to this arbitrary file write issue. The recommended action is to upgrade to a non-affected version of remotion as soon as possible.

In addition to upgrading, you should review your environments for any potential unauthorized file writes that may have occurred as a result of this vulnerability. The primary sources should be consulted for the most up-to-date information and guidance.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If remotion is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats