Executive brief
Next.js is a popular React-based web framework used by developers to build websites and applications. A vulnerability in versions 10.0.5 through 11.0.1 could allow attackers to craft specially encoded URLs that redirect users to external malicious sites when certain error pages are statically generated, potentially enabling phishing attacks against application users.
Technical details
This is an open redirect vulnerability (CWE-601) in Next.js affecting the error page handling when pages/_error.js is statically generated. Specially encoded paths bypass validation and cause redirects to arbitrary external URLs. The vulnerability is triggered by static generation of the error page (particularly in versions 10.0.5–10.2.0 and 11.0.0–11.0.1 without getInitialProps or with next export). Network-reachable applications are affected; attackers craft malicious links from a trusted domain to redirect users. Deployments using pages/404.js or hosted on Vercel are not affected. The fix was released in Next.js v11.1.0.
Affected products
- Vercel Next.js 10.0.5 through 11.0.1
Timeline
- 2021-08-12: disclosed
- 2021-08-12: patched: v11.1.0 released