Next.js 是一个用于构建全栈 Web 应用的 React 框架。从版本 16.0.0 到 16.3.8, 开发服务器暴露了一个 Model Context Protocol(MCP,模型上下文协议)端点,且未可靠地限制跨站请求。开发者访问的恶意网站可以访问该端点,从而读取项目的磁盘路径、来自错误报告的源代码片段、路由列表以及开发日志。生产环境部署中不提供此端点。该问题已在版本 16.3.8 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94483 | 8.3 HIGH | Next.js: Server-Side Request Forgery in Image Optimization |
| CVE-2026-94484 | 6.3 MEDIUM | Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitu |
| CVE-2026-94544 | 6.3 MEDIUM | Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and p |
| CVE-2026-94543 | 6.3 MEDIUM | Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications |
| CVE-2026-94486 | 2.3 LOW | Next.js: Information disclosure in the Next.js development server's Model Context Protocol |
No comments yet