GHSA-2p39-2jf3-fv2q

Suggest an improvement
Source
https://github.com/advisories/GHSA-2p39-2jf3-fv2q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-2p39-2jf3-fv2q/GHSA-2p39-2jf3-fv2q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2p39-2jf3-fv2q
Aliases
Published
2026-08-20T18:35:11Z
Modified
2026-08-20T18:48:09Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
next-video: Unauthenticated arbitrary file read via /api/video request handler
Details

Impact

The HTTP route handler exported by next-video/request-handler — which the README instructs consumers to mount at /api/video — allows an unauthenticated remote attacker to read arbitrary .json files from the production filesystem of any application following the documented setup.

The handler's GET endpoint accepts a url query parameter and uses it to locate and serve a JSON asset descriptor from disk. The only guard between "remote URL" and "local file path" is a regex check for ^https?://. Any value that does not match that prefix is treated as a local path, .json is appended, and the file is read with fs.readFile and returned in the HTTP response — with no authentication, no path canonicalization, and no traversal guard.

On a typical Next.js deployment this exposes, at minimum:

  • The Next.js Server Actions AES encryption key (.next/server/server-reference-manifest.json)
  • The Next.js Preview/Draft Mode keys (previewModeId, previewModeSigningKey, previewModeEncryptionKey)
  • Internal build manifests, route registries, and absolute runtime paths
  • Application-specific asset metadata (e.g. Mux uploadId, assetId, playbackId values stored in videos/*.json)

Any application that mounted /api/video following the documented one-liner is affected.

Patches

2.8.1

Workarounds

Until a patched version is available, wrap the exported handler in your own route file and validate the url parameter before passing it through:

  • Reject any url value that does not begin with https://, or that does not match a known allowlist of trusted remote hosts.
  • Alternatively, remove the /api/video route entirely if your application only uses build-time import of local video files and does not use <Video src="https://..."> with string URLs at runtime.

References

  • src/request-handler.ts — the vulnerable GET handler
  • src/assets.ts — getAssetPath(), where the local-vs-remote branching occurs
  • src/utils/utils.ts — isRemote(), the sole guard between the two branches
  • src/config.ts — loadAsset(), which performs the unconstrained fs.readFile
Database specific
{
    "cwe_ids":  [
        "CWE-200"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-20T18:35:11Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / next-video

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.8.1

Database specific

last_known_affected_version_range
"<= 2.8.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-2p39-2jf3-fv2q/GHSA-2p39-2jf3-fv2q.json"