next is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
Inline beforeInteractive script serialization can embed untrusted input without sufficient escaping. Attacker-controlled content can break script boundaries and execute arbitrary JavaScript in the browser. This affects applications that pass untrusted data into these script props. The fix HTML-escapes serialized script content before insertion.
You are affected if you are using a version that falls within the vulnerable range.
next is vulnerable to Cross-Site Scripting (XSS) in versions 13.0.0 - 15.5.15 and 16.0.0 - 16.2.4.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant