---
id: CVE-2026-30121
aliases:
  - GHSA-g6pc-6676-c23j
title: 'Remotion: arbitrary file write vulnerability'
summary: 'Remotion: arbitrary file write vulnerability'
severity: critical
cvss: 9.1
cwe:
  - CWE-123
vendor: remotion
product: remotion
ecosystem: npm
affected:
  - remotion < 4.0.410
patched:
  - remotion 4.0.410
published: '2026-06-15'
updated: '2026-06-19'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-g6pc-6676-c23j'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-30121'
  - url: >-
      https://github.com/EaEa0001/security-advisories/blob/main/CVE-2026-30121.md
  - url: 'https://github.com/remotion-dev/remotion/pull/6378'
  - url: 'https://github.com/remotion-dev/remotion/releases/tag/v4.0.410'
  - url: 'https://github.com/advisories/GHSA-g6pc-6676-c23j'
tags:
  - ghsa
  - npm
epss: 0.00478
epssPercentile: 0.38663
ingestedAt: '2026-07-07T15:41:58.393Z'
---

## Overview

remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.

## Affected packages

- `remotion < 4.0.410`

## Remediation

Upgrade to a patched release:

- `remotion 4.0.410`
