Impact
This vulnerability causes a remote attacker, via an encoded Windows path separator in a route segment, to bypass file system isolation and read private build data—including the server‑reference‑manifest encryption key. The disclosure of the key allows execution of arbitrary code within the affected Next.js application. The weakness is a path traversal issue.
Affected Systems
Versions of Next.js from 13.4.0 up through 15.5.23 and 16.3.2 that use the Pages Router or App Router without Cache Components on Windows‑hosted servers are affected. The issue is addressed in releases 15.5.24 and 16.3.3.
Risk and Exploitability
The CVSS score of 9 indicates a critical severity. EPSS data are not available, so exploitation probability cannot be quantified, yet the vulnerability is listed in a public advisory and not yet in the CISA KEV catalog. The likely attack vector is a remote HTTP request targeting a Windows‑hosted Next.js application, exploiting the lack of backslash escaping in route segments. Once the attacker controls the cache key, remote code execution can be achieved.
OpenCVE Enrichment