next is vulnerable to Information Disclosure
63
Medium Risk
Webpack builds of next drop the dynamicParams export when they load metadata image routes such as opengraph-image and twitter-image. A request for a dynamic segment that generateStaticParams() left out still runs that image route. The response can expose content the route was configured not to generate. The fix re-exports dynamicParams so the segment option is applied.
You are affected if you are using a version that falls within the vulnerable range and you build metadata image routes with webpack while dynamicParams is false.
next is vulnerable to Information Disclosure in versions 16.0.0 - 16.3.7.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.