Cross-Site Request Vulnerability in Next.js Framework by Vercel
CVE-2026-94485

6.3MEDIUM

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-94485?

The Next.js framework by Vercel, specifically versions from 16.0.0 to 16.3.8, has a vulnerability where the next dev development server inadvertently exposes a Model Context Protocol endpoint. This endpoint does not effectively restrict cross-site requests, enabling malicious websites accessed by developers to exploit this flaw. As a result, attackers can potentially read sensitive information, including the project's disk location, snippets of source code from error reports, and development logs. Fortunately, this vulnerability was addressed in version 16.3.8, which secured the endpoint for production deployments.

Affected Version(s)

next.js >= 16.0.0, < 16.3.8

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.