Unauthenticated Path Traversal Vulnerability in Next.js Video Library by Mux Inc.
CVE-2026-54150
6.9MEDIUM
What is CVE-2026-54150?
The Next.js video library by Mux Inc. contains a vulnerability that allows unauthenticated remote attackers to exploit the GET endpoint at /api/video. The underlying issue stems from improper handling of URL parameters and insufficient path validation, which could lead to unauthorized access to sensitive application files. Specifically, attackers can manipulate the request to bypass directory restrictions and read arbitrary JSON files, potentially exposing confidential information such as server-action encryption material and build manifests. This vulnerability has been addressed in version 2.8.1 of the library.
Affected Version(s)
next-video < 2.8.1
