Nextjs v2.4.1 LFI

Published on 01 Oct 2021
Vulnerability

Next.js is a server-rendered React framework with a simple approach.Next.js versions prior to 2.4.1 include a directory traversal bug. The / next and /static request namespaces are affected by this problem. An attacker can create a request that allows them to access potentially sensitive data in your filesystem.

Mitigation / Precaution

In order to patch this vulnerability, we suggest you update Nextjs to the latest version.

Prathap
Written by
Co-founder, Director

Prathap has around 20 years of experience and has worked on various projects in leading companies like Hitachi, Toshiba, Schneider Electric, ABB, Panasonic, and MicroFuzzy. His expertise lies in architecting, designing, and developing secure projects covering various aspects of software development, processes, and methodology.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo