Executive brief
Next.js is a popular React framework used to build web applications. A directory traversal vulnerability in the /_next request namespace allows attackers to access sensitive files outside the intended application directory by manipulating file paths, potentially exposing source code, configuration files, and other confidential data without requiring authentication.
Technical details
This vulnerability is a classic path traversal (CWE-22) issue in Next.js versions 1.0.0 through 4.2.2, where the /_next request handler does not properly sanitize user-supplied path components. An attacker can exploit this via a network request using path traversal sequences (such as ../ or similar techniques) to navigate outside the restricted directory and read arbitrary files on the server. The vulnerability requires no authentication or user interaction and is remotely exploitable. The fix was released in Next.js version 4.2.3.
Affected products
- Vercel Next.js 1.0.0 through 4.2.2
Timeline
- 2018-01-24: disclosed