Impact
next-video is a library that adds video to Next.js apps. Prior to 2.8.1, its GET endpoint at /api/video accepts an unauthenticated url query parameter that is treated by isRemote() as a local path when no HTTP(S) prefix is present. The value is then passed to getAssetPath() and loadAsset(), which appends a JSON suffix and reads the file with fs.readFile without resolving or validating that the path remains inside the configured video folder. This oversight allows an attacker to trigger a path‑escape and read arbitrary JSON files that the application process can access, such as server‑action encryption material, preview‑mode keys, build manifests, route metadata, absolute paths, and video asset identifiers. The vulnerability is mitigated in version 2.8.1.
Affected Systems
The flaw resides in muxinc’s next‑video component. All releases before version 2.8.1 are vulnerable when the request handler is exposed under /api/video. Applications that do not mount the handler are not affected through this route. Versions 2.8.1 and newer contain a fix that validates paths and limits reads to the correct asset folder.
Risk and Exploitability
The CVSS base score of 6.9 indicates moderate severity. Because the endpoint lacks authentication an attacker can trigger the read with a simple HTTP GET. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, but the ability to read sensitive local files creates a significant confidentiality risk. An exploit would involve sending a crafted query string to the /api/video endpoint, causing the server to read the requested file and return its contents.
OpenCVE Enrichment
Github GHSA