Vercel Next.js
cpe:2.3:a:vercel:next.js:*:*:*:*:node.js:*:*
- <= 10.0.5, >= 10.2.0
- <= 11.0.1
A vulnerability allowing open redirects has been identified in Next.js versions 10.0.5 prior to 10.2.0 and 11.0.0 prior to 11.0.1, when using 'pages/_error.js' without 'getInitialProps' or with 'next export'. This issue does not affect Vercel deployments or those with 'pages/404.js'. The vulnerability arises from improperly handled path parsing, which could be exploited to redirect users from a trusted domain to an attacker's domain, potentially leading to phishing attacks.
Exploitation of this vulnerability could allow for open redirects, where users are sent from a trusted site to an external site of the attacker's choice.
Users can upgrade to Next.js version 11.1.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.