Vercel Next.js
cpe:2.3:a:vercel:next.js:*:*:*:*:node.js:*:*
- < 9.3.2
A directory traversal vulnerability has been identified in Next.js versions prior to 9.3.2. This vulnerability allows attackers to craft requests that access files within the .next (dist) directory. The issue does not affect files outside of this directory. Typically, the dist directory contains build assets, unless the application intentionally places other files there. The vulnerability arises when the application is deployed using 'next start', leaving it open to exploitation.
Exploitation of this vulnerability could lead to unauthorized access to files in the .next directory, potentially exposing sensitive information or code.
Users are advised to upgrade to Next.js version 9.3.2 or later. Instructions for upgrading are available in the Next.js release notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.