Description
next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts an unauthenticated url query parameter, while src/utils/utils.ts isRemote() treats any value without an HTTP or HTTPS prefix as a local path. src/request-handler.ts passes that value through src/assets.ts getAssetPath() to src/config.ts loadAsset(), which appends a JSON suffix and uses fs.readFile without canonicalizing the path or verifying that it remains inside the configured video folder. A remote attacker can therefore escape the intended asset directory and read JSON files accessible to the application process, including Next.js server-action encryption material, preview-mode keys, build manifests, route metadata, absolute paths, and application video asset identifiers. Applications that do not expose the runtime request handler are not affected through this route. This issue is fixed in version 2.8.1.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: File Read via Unauthenticated Request
Action: Immediate Patch
AI Analysis

Impact

next-video is a library that adds video to Next.js apps. Prior to 2.8.1, its GET endpoint at /api/video accepts an unauthenticated url query parameter that is treated by isRemote() as a local path when no HTTP(S) prefix is present. The value is then passed to getAssetPath() and loadAsset(), which appends a JSON suffix and reads the file with fs.readFile without resolving or validating that the path remains inside the configured video folder. This oversight allows an attacker to trigger a path‑escape and read arbitrary JSON files that the application process can access, such as server‑action encryption material, preview‑mode keys, build manifests, route metadata, absolute paths, and video asset identifiers. The vulnerability is mitigated in version 2.8.1.

Affected Systems

The flaw resides in muxinc’s next‑video component. All releases before version 2.8.1 are vulnerable when the request handler is exposed under /api/video. Applications that do not mount the handler are not affected through this route. Versions 2.8.1 and newer contain a fix that validates paths and limits reads to the correct asset folder.

Risk and Exploitability

The CVSS base score of 6.9 indicates moderate severity. Because the endpoint lacks authentication an attacker can trigger the read with a simple HTTP GET. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, but the ability to read sensitive local files creates a significant confidentiality risk. An exploit would involve sending a crafted query string to the /api/video endpoint, causing the server to read the requested file and return its contents.

Generated by OpenCVE AI on September 20, 2026 at 23:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade next-video to version 2.8.1 or newer.
  • If an immediate upgrade is not possible, disable or protect the /api/video endpoint with authentication or remove it entirely from deployment.
  • Validate that the video assets directory is correctly configured and that no untrusted paths are resolvable by the application.

Generated by OpenCVE AI on September 20, 2026 at 23:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2p39-2jf3-fv2q next-video: Unauthenticated arbitrary file read via /api/video request handler
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Muxinc
Muxinc next-video
Vendors & Products Muxinc
Muxinc next-video

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts an unauthenticated url query parameter, while src/utils/utils.ts isRemote() treats any value without an HTTP or HTTPS prefix as a local path. src/request-handler.ts passes that value through src/assets.ts getAssetPath() to src/config.ts loadAsset(), which appends a JSON suffix and uses fs.readFile without canonicalizing the path or verifying that it remains inside the configured video folder. A remote attacker can therefore escape the intended asset directory and read JSON files accessible to the application process, including Next.js server-action encryption material, preview-mode keys, build manifests, route metadata, absolute paths, and application video asset identifiers. Applications that do not expose the runtime request handler are not affected through this route. This issue is fixed in version 2.8.1.
Title next-video: Unauthenticated arbitrary file read via /api/video request handler
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Muxinc Next-video
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:03:28.592Z

Reserved: 2026-06-11T21:15:33.871Z

Link: CVE-2026-54150

cve-icon Vulnrichment

Updated: 2026-09-14T19:03:25.256Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:52.277

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')