next is vulnerable to Sensitive Information Disclosure
63
Medium Risk
In Next.js applications using the App Router, identifiers for Server Actions (use server) and use cache endpoints are emitted into publicly served client artifacts such as static chunks. An unauthenticated visitor can read these artifacts to enumerate internal Server Function endpoints even on pages that are otherwise gated by authentication. On its own this is a reconnaissance primitive, but it increases risk when combined with weak authorization at the function boundary. The fix reduces exposure of these internal endpoint identifiers.
You are affected if you are using a version that falls within the vulnerable range and your application uses the App Router with Server Actions or use cache endpoints.
next is vulnerable to Sensitive Information Disclosure in versions 13.0.0 - 15.5.20 and 16.0.0 - 16.2.10.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant