Intel

AIKIDO-2026-907992

next is vulnerable to Information Disclosure

Information DisclosureCVE-2026-94486 Published 5 days ago

23

Low Risk

This Affects:

JSnext
16.0.0 - 16.3.7
Fixed in 16.3.8
Are you affected? Scan for Free

TL;DR

The next dev server exposes a Model Context Protocol endpoint at /_next/mcp without checking which site sent the request. A site open in the same browser can read development data from that endpoint, including the project path on disk, error snippets, the route list, and dev logs. Production deployments do not expose this endpoint. The fix matches /_next/mcp exactly and applies the dev server cross site check to it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run the development server with next dev.

Background info

next is vulnerable to Information Disclosure in versions 16.0.0 - 16.3.7.

How to fix this

Upgrade the next library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform