Intel

AIKIDO-2026-16130

next is vulnerable to Information Disclosure

Information DisclosureCVE-2026-94485 Published 5 days ago

63

Medium Risk

This Affects:

JSnext
16.0.0 - 16.3.7
Fixed in 16.3.8
Are you affected? Scan for Free

TL;DR

Webpack builds of next drop the dynamicParams export when they load metadata image routes such as opengraph-image and twitter-image. A request for a dynamic segment that generateStaticParams() left out still runs that image route. The response can expose content the route was configured not to generate. The fix re-exports dynamicParams so the segment option is applied.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you build metadata image routes with webpack while dynamicParams is false.

Background info

next is vulnerable to Information Disclosure in versions 16.0.0 - 16.3.7.

How to fix this

Upgrade the next library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform