Next.js 是一个用于构建全栈 Web 应用的 React 框架。在版本 16.0.0 至 16.3.8 之间,next dev 开发服务器暴露了一个模型上下文协议(Model Context Protocol)端点,但未可靠地限制跨站请求。开发人员访问的恶意网站可以访问该端点,从而读取项目的磁盘位置、来自错误报告的源代码片段、路由清单以及开发日志。生产部署环境不会提供此端点。该问题已在版本 16.3.8 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94483 | 8.3 HIGH | Next.js: Server-Side Request Forgery in Image Optimization |
| CVE-2026-94484 | 6.3 MEDIUM | Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitu |
| CVE-2026-94485 | 6.3 MEDIUM | Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicPar |
| CVE-2026-94544 | 6.3 MEDIUM | Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and p |
| CVE-2026-94543 | 6.3 MEDIUM | Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications |
No comments yet