Description
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk location, source code snippets from error reports, route inventory, and development logs. Production deployments do not serve this endpoint. This issue is fixed in version 16.3.8.
Published: 2026-10-02
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure via the Next.js development server endpoint
Action: Apply update
AI Analysis

Impact

The vulnerability arises from the Next.js development server exposing a Model Context Protocol (MCP) endpoint that does not enforce proper cross‑site request restrictions. When a developer is running the server, a malicious website can send requests to this MCP endpoint and retrieve sensitive development data, including the project’s disk location, snippets of source code from error reports, a list of all defined routes, and development logs. This access is not limited to authenticated users and can be performed through a normal web browser visit. The exposed data could assist attackers in building an attack surface or jumping to further compromise exploitation steps.

Affected Systems

The issue affects the Vercel Next.js framework, versions 16.0.0 through 16.3.8 inclusive. This applies only to the local development server and has been fixed in version 16.3.8.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The likely attack vector is a malicious website visited by a developer who is running the development server, allowing the attacker to issue cross‑site requests to the MCP endpoint from the developer’s browser. Since production deployments do not serve this endpoint, the damage is confined to the development environment. However, exposing source code or project structure could aid future attacks or facilitate social engineering on the same network.

Generated by OpenCVE AI on October 2, 2026 at 16:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Next.js to version 16.3.8 or later to apply the vendor‑supplied fix
  • Configure the development server so that it listens only on localhost or a tightly controlled network segment to prevent external access
  • Avoid browsing untrusted or arbitrary websites while the development server is running to eliminate the cross‑site request threat

Generated by OpenCVE AI on October 2, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Vercel
Vercel next.js
Vendors & Products Vercel
Vercel next.js

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Description Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk location, source code snippets from error reports, route inventory, and development logs. Production deployments do not serve this endpoint. This issue is fixed in version 16.3.8.
Title Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass
Weaknesses CWE-346
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T16:05:57.266Z

Reserved: 2026-09-21T17:25:42.292Z

Link: CVE-2026-94485

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T16:16:51.777

Modified: 2026-10-02T16:16:51.777

Link: CVE-2026-94485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:30:14Z

Weaknesses