Executive brief
Next.js is a popular web application framework that developers use to build fast, production-ready applications. Server Actions is a feature that allows developers to execute code on the server in response to user actions. A vulnerability allows attackers who can modify the Host header in network requests to trick the Next.js application server into making requests that appear to originate from itself, potentially exposing sensitive internal data or services accessible only from within the application's network.
Technical details
A Server-Side Request Forgery (CVSS-918) vulnerability exists in Next.js Server Actions when running in self-hosted environments. The vulnerability is triggered when a Server Action performs a redirect to a relative path beginning with "/" and an attacker modifies the Host header in the request. The attack requires no authentication or user interaction and can be exploited over the network, but affects only self-hosted Next.js instances (not those using host-based routing like Vercel). An attacker can make the server issue requests that appear to originate from the application server itself, potentially accessing internal resources or services. The vulnerability was fixed in Next.js 14.1.1 via pull request #62561; users running versions 13.4.0 through 14.1.0 should upgrade immediately.
Affected products
- Vercel Next.js >=13.4.0, <14.1.1
Timeline
- 2024-05-09: disclosed
- 2024-05-09: patched: Fixed in Next.js 14.1.1