Unauthenticated Path Traversal Vulnerability in Next.js Video Library by Mux Inc.
CVE-2026-54150

6.9MEDIUM

Key Information:

Vendor

Muxinc

Vendor
CVE Published:
14 September 2026

What is CVE-2026-54150?

The Next.js video library by Mux Inc. contains a vulnerability that allows unauthenticated remote attackers to exploit the GET endpoint at /api/video. The underlying issue stems from improper handling of URL parameters and insufficient path validation, which could lead to unauthorized access to sensitive application files. Specifically, attackers can manipulate the request to bypass directory restrictions and read arbitrary JSON files, potentially exposing confidential information such as server-action encryption material and build manifests. This vulnerability has been addressed in version 2.8.1 of the library.

Affected Version(s)

next-video < 2.8.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.