Directory Traversal in Next.js versions below 9.3.2
62Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 4.4epss 43%
from disclosure to weapon
Published on NVDMar 30
VulnCheck+2184d
exploitation probability
43%top 1% of all CVEs
observed exploitation
yesVulnCheck
Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. This issue is fixed in version 9.3.2.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
zeit · next.js