Executive brief
Next.js is a popular React web framework used to build web applications. On Windows-hosted servers, a path traversal vulnerability in the routing system allows unauthenticated attackers to execute arbitrary code remotely. This affects applications using the Pages or App router without Cache Component, potentially leading to complete compromise of the web server and access to sensitive application data.
Technical details
This vulnerability is a path traversal (CWE-22) flaw in Next.js versions 13.4.0 through 15.5.23 and 16.0.0 through 16.3.2 affecting applications deployed on Windows filesystem. The flaw exists in the routing system when using Pages or App router without Cache Component enabled. An unauthenticated attacker over the network can send specially crafted requests that traverse the directory structure due to improper pathname handling on Windows systems, bypassing path restrictions. The attack vector is network-based with high complexity but requires no authentication or user interaction. Successful exploitation results in remote code execution with full system impact including data confidentiality, integrity, and availability compromise. Patches are available in versions 15.5.24 and 16.3.3.
Affected products
- Vercel Next.js >=13.4.0, <15.5.24; >=16.0.0, <16.3.3
Timeline
- 2026-08-25: disclosed: Published by security researcher
- 2026-09-01: advisory: NVD published
- 2026-09-08: advisory: GitHub Advisory Database published and reviewed
- 2026: patched: Patched in versions 15.5.24 and 16.3.3
References
- https://api.github.com/users/evolutionstorm
- https://github.com/evolutionstorm
- https://api.github.com/users/evolutionstorm/gists%7B/gist_id%7D
- https://api.github.com/users/evolutionstorm/repos
- https://avatars.githubusercontent.com/u/51437180?v=4
- https://api.github.com/users/evolutionstorm/events%7B/privacy%7D