Critical security flaw in Next.js could spell big trouble for JavaScript users




  • Researchers spot critical vulnerability in Next.js
  • If authorizations happen in middleware, they could be bypassed in older versions
  • A patch, and a temporary workaround, are both available, so update now

Experts have warned there is a critical severity flaw in the Next.js open source web development framework which allows threat actors to bypass authorization checks.

Security researcher Rachid.A from Zhero Web Security posted an in-depth analysis of the findings, with the vulnerability tracked as CVE-2025-29927, and receiving a severity score of 9.1/10 (critical).

https://cdn.mos.cms.futurecdn.net/YbizeHRMkF5QLe6eeYypqc-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img