next is vulnerable to Information Disclosure
23
Low Risk
The next dev server exposes a Model Context Protocol endpoint at /_next/mcp without checking which site sent the request. A site open in the same browser can read development data from that endpoint, including the project path on disk, error snippets, the route list, and dev logs. Production deployments do not expose this endpoint. The fix matches /_next/mcp exactly and applies the dev server cross site check to it.
You are affected if you are using a version that falls within the vulnerable range and you run the development server with next dev.
next is vulnerable to Information Disclosure in versions 16.0.0 - 16.3.7.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.