Executive brief
Next.js is a popular web development framework used to build React-based websites. A security flaw was found that allows unauthorized users to access files on the server that should be restricted. This could lead to the exposure of sensitive application code or internal configuration files, potentially compromising the security of the entire web application.
Technical details
A directory traversal vulnerability (CWE-22) exists in Next.js versions prior to 2.4.1. The vulnerability is located within the request handling for the /_next and /static namespaces. An unauthenticated remote attacker can use specially crafted requests containing path traversal sequences (e.g., '../') to escape the intended directory and access sensitive files on the host filesystem. While containerized or chrooted environments may limit the scope of exposure, the flaw generally allows access to frontend JavaScript components and potentially other server-side assets. The issue was resolved by implementing stricter URL validation in the serveStatic method.
Affected products
- Vercel Next.js < 2.4.1, 3.0.0-beta1 to 3.0.0-beta6
Timeline
- 2017-11-17: disclosed: NVD publication date
- 2017-12-05: advisory: GitHub Advisory published
- 2017-06-02: patched: Version 2.4.1 released with fix