Cross-Site Request Vulnerability in Next.js Framework by Vercel
CVE-2026-94486

2.3LOW

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-94486?

A security issue in Next.js, a popular React framework, exposes a Model Context Protocol endpoint on its development server for versions 16.0.0 through 16.3.8. This vulnerability allows a malicious website visited by developers to access potentially sensitive data, including project disk locations, source code snippets from error reports, route inventories, and development logs. This endpoint is not available in production deployments, but its exposure in a development environment poses significant risks. The issue has been addressed in version 16.3.8.

Affected Version(s)

next.js >= 16.0.0, < 16.3.8

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.