GHSA-39w2-rjm5-chcv

Suggest an improvement
Source
https://github.com/advisories/GHSA-39w2-rjm5-chcv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-39w2-rjm5-chcv/GHSA-39w2-rjm5-chcv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-39w2-rjm5-chcv
Aliases
Published
2026-10-07T20:31:51Z
Modified
2026-10-07T20:45:05Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Next.js has information disclosure in development server's Model Context Protocol endpoint
Details

The Next.js development server (next dev) exposes a Model Context Protocol endpoint that does not verify which website a request originates from, allowing a malicious website visited by the developer to read sensitive development data — including the project's location on disk, source code snippets from error reports, the route inventory, and development logs. Only applications run with next dev are affected. Production deployments do not serve this endpoint.

Database specific
{
    "cwe_ids": [
        "CWE-346"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T20:31:51Z",
    "nvd_published_at": "2026-10-02T16:16:51Z",
    "severity": "LOW"
}
References

Affected packages

npm / next

Package

Affected ranges

Type
SEMVER
Events
Introduced
16.0.0
Fixed
16.3.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-39w2-rjm5-chcv/GHSA-39w2-rjm5-chcv.json"