Cross-Site Request Vulnerability in Next.js Framework by Vercel
CVE-2026-94485
6.3MEDIUM
What is CVE-2026-94485?
The Next.js framework by Vercel, specifically versions from 16.0.0 to 16.3.8, has a vulnerability where the next dev development server inadvertently exposes a Model Context Protocol endpoint. This endpoint does not effectively restrict cross-site requests, enabling malicious websites accessed by developers to exploit this flaw. As a result, attackers can potentially read sensitive information, including the project's disk location, snippets of source code from error reports, and development logs. Fortunately, this vulnerability was addressed in version 16.3.8, which secured the endpoint for production deployments.
Affected Version(s)
next.js >= 16.0.0, < 16.3.8