CVE-2026-54130: Unauthenticated arbitrary file read via /api/video in next-video npm package
Security Advisory
CVE-2026-54130
Medium
muxinc/next-video
Affected:
- next-video <= 2.8.0
Fixed in:
- 2.8.1
Referenced CVEs:
CVE-2026-54150 · 6.9
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.