Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-5284 | Next.js versions before 9.3.2 have a directory traversal vulnerability. Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. This issue is fixed in version 9.3.2. NVD description · AI analysis pending | 4.3 | 44% |
| — | ||
| CVE-2019-5417 +1 in the same advisory: …5415 | A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server. A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2018-18282 | Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page. Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page. NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2018-3712 +1 in the same advisory: …3718 | serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a ma serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a malicious user to view the contents of any directory with known path. NVD description · AI analysis pending | 6.5 group max | 2% | PoC |
| — | |
| CVE-2018-3809 | Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored. Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored. NVD description · AI analysis pending | 5.3 | 1% | PoC |
| — | |
| CVE-2018-6184 | ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace. ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace. NVD description · AI analysis pending | 7.5 | 9% |
| — | ||
| CVE-2017-16877 | ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information. ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information. NVD description · AI analysis pending | 7.5 | 14% |
| — |