Executive brief
Next.js is a popular React-based web framework used by developers to build and test web applications. In development mode, the framework includes a hot module reloading (HMR) system that communicates with the development server via WebSocket. A security flaw allows attackers to bypass cross-site request forgery (CSRF) protections on internal dev endpoints by spoofing a null origin header, potentially giving malicious code access to sensitive development functionality when a developer visits an attacker-controlled website.
Technical details
The vulnerability exists in Next.js dev server's WebSocket origin validation logic, which failed to properly validate the Origin: null header case even when allowedDevOrigins was configured. The affected component is the HMR (Hot Module Reloading) WebSocket CSRF protection mechanism for internal development endpoints. The attack requires network-level access to reach the dev server and relies on user interaction (a developer visiting attacker-controlled content in the same browser session). An attacker can establish WebSocket connections to internal dev endpoints and interact with sensitive development functionality that should have been blocked by origin checks. This issue affects only next dev (development mode); next start (production mode) is unaffected. The vulnerability was patched in version 16.1.7 by implementing proper Origin: null validation through the same cross-site origin-allowance checks applied to other origins.
Affected products
- Vercel Next.js >=16.0.1, <16.1.7
Timeline
- 2026-03-17: disclosed: GHSA-jcc7-9wpm-mj36 published
- 2026-03-17: patched: Fix released in Next.js 16.1.7