---
id: CVE-2026-30120
aliases:
  - GHSA-2jqp-f4gr-44fr
title: 'Remotion: remote code execution (RCE) vulnerability'
summary: 'Remotion: remote code execution (RCE) vulnerability'
severity: critical
cvss: 9.8
cwe:
  - CWE-94
vendor: remotion
product: remotion
ecosystem: npm
affected:
  - remotion < 4.0.410
patched:
  - remotion 4.0.410
published: '2026-06-15'
updated: '2026-06-19'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-2jqp-f4gr-44fr'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-30120'
  - url: >-
      https://github.com/EaEa0001/security-advisories/blob/main/CVE-2026-30120.md
  - url: 'https://github.com/remotion-dev/remotion/pull/6378'
  - url: 'https://github.com/remotion-dev/remotion/releases/tag/v4.0.410'
  - url: 'https://github.com/advisories/GHSA-2jqp-f4gr-44fr'
tags:
  - ghsa
  - npm
epss: 0.00869
epssPercentile: 0.57002
ingestedAt: '2026-07-07T15:41:58.395Z'
---

## Overview

remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.

## Affected packages

- `remotion < 4.0.410`

## Remediation

Upgrade to a patched release:

- `remotion 4.0.410`
