Skip to content

Open Redirect in Next.js versions between 9.5.0 and 9.5.3

Moderate
timneutkens published GHSA-x56p-c8cg-q435 Oct 8, 2020

Package

npm next (npm)

Affected versions

9.5.0 <= 9.5.3

Patched versions

9.5.4

Description

Impact

  • Affected: Users of Next.js between 9.5.0 and 9.5.3
  • Not affected: Deployments on Vercel (https://vercel.com) are not affected
  • Not affected: Deployments using next export

We recommend everyone to upgrade regardless of whether you can reproduce the issue or not.

Patches

https://github.com/vercel/next.js/releases/tag/v9.5.4

References

https://github.com/vercel/next.js/releases/tag/v9.5.4

Severity

Moderate

CVE ID

CVE-2020-15242

Weaknesses

No CWEs