GHSA-f87g-xv8r-7p7x

Suggest an improvement
Source
https://github.com/advisories/GHSA-f87g-xv8r-7p7x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-f87g-xv8r-7p7x/GHSA-f87g-xv8r-7p7x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f87g-xv8r-7p7x
Aliases
Published
2026-10-07T20:31:33Z
Modified
2026-10-07T20:45:04Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass
Details

In Next.js App Router applications built with webpack, metadata image routes such as opengraph-image and twitter-image ignore the dynamicParams route segment option. An attacker can request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams().

Database specific
{
    "cwe_ids": [
        "CWE-346"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T20:31:33Z",
    "nvd_published_at": "2026-10-02T16:16:51Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / next

Package

Affected ranges

Type
SEMVER
Events
Introduced
16.0.0
Fixed
16.3.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-f87g-xv8r-7p7x/GHSA-f87g-xv8r-7p7x.json"