MEDIUM 6.1 npm
Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page
GHSA-qw96-mm2g-c8m7 · CVE-2018-18282
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
Ready to move
Start Securing
Free, no credit card | First findings in minutes