Impact
The vulnerability arises from the Next.js development server exposing a Model Context Protocol (MCP) endpoint that does not enforce proper cross‑site request restrictions. When a developer is running the server, a malicious website can send requests to this MCP endpoint and retrieve sensitive development data, including the project’s disk location, snippets of source code from error reports, a list of all defined routes, and development logs. This access is not limited to authenticated users and can be performed through a normal web browser visit. The exposed data could assist attackers in building an attack surface or jumping to further compromise exploitation steps.
Affected Systems
The issue affects the Vercel Next.js framework, versions 16.0.0 through 16.3.8 inclusive. This applies only to the local development server and has been fixed in version 16.3.8.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The likely attack vector is a malicious website visited by a developer who is running the development server, allowing the attacker to issue cross‑site requests to the MCP endpoint from the developer’s browser. Since production deployments do not serve this endpoint, the damage is confined to the development environment. However, exposing source code or project structure could aid future attacks or facilitate social engineering on the same network.
OpenCVE Enrichment