Vercel Next.js
cpe:2.3:a:vercel:next.js:*:*:*:*:node.js:*:*
- >= 10.0.0, <= 12.0.10
A vulnerability allowing user interface misrepresentation of critical information has been identified in Next.js, a React framework. This issue affects versions 10.0.0 prior to 12.1.0. The vulnerability arises when the 'next.config.js' file includes an 'images.domains' array with a host that permits user-uploaded SVGs. If the 'images.loader' is set to anything other than the default, the vulnerability does not apply. Exploitation of this vulnerability could lead to improper handling of content security policies in the image optimization API, potentially allowing malicious SVGs to be processed.
Exploitation of this vulnerability could result in improper content security policy handling, allowing maliciously crafted SVG images to be processed by the application, which could lead to user interface misrepresentation or other unintended consequences.
Users can upgrade to Next.js version 12.1.0, which addresses this vulnerability. Alternatively, as a workaround, the 'next.config.js' file can be modified to use a different loader configuration than the default.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.