drupal/next is vulnerable to Access Bypass
95
Critical Risk
Affected versions of this package are vulnerable to access bypass through insecure cors behavior: the module automatically enables CORS with Access-Control-Allow-Origin: *, overriding any existing services.yml settings and allowing any origin to make cross-origin requests without administrator approval. All installations are affected because this behavior cannot be disabled. Updating the module resolves the issue—upgrade to Next.js 2.0.1 for Drupal 10/11 or Next.js 1.6.4 for Drupal 9—and then review your CORS configuration in sites/default/services.yml, especially if you previously relied on the module’s automatic settings.
You are affected if you are using a version that falls within the vulnerable range.
drupal/next is vulnerable to Access Bypass in versions 0.0.1 - 1.6.3 and 2.0.0 - 2.0.0.
Upgrade the drupal/next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant