Vercel Next.js
cpe:2.3:a:vercel:next.js:*:*:*:*:node.js:*:*
- >= 9.5.0, < 9.5.4
A vulnerability allowing open redirects has been identified in Next.js versions 9.5.0 prior to 9.5.4. This issue arises from the handling of specially encoded paths with the trailing slash redirect, allowing redirection to external sites. While this redirect does not directly harm users, it could facilitate phishing attacks by directing users from a trusted domain to an attacker's domain.
Exploitation of this vulnerability could lead to open redirect behavior, allowing for potential phishing attacks.
Users are advised to upgrade to Next.js version 9.5.4 or later. Instructions for upgrading are available in the Next.js release notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.