Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 npm

XSS in Image Optimization API for Next.js

GHSA-9gr3-7897-pp7m · CVE-2021-39178

Published · Modified

Description

Impact

  • Affected: All of the following must be true to be affected
    • Next.js between version 10.0.0 and 11.1.0
    • The next.config.js file has images.domains array assigned
    • The image host assigned in images.domains allows user-provided SVG
  • Not affected: The next.config.js file has images.loader assigned to something other than default
  • Not affected: Deployments on Vercel are not affected

Patches

Next.js v11.1.1

Ready to move

Start Securing

Free, no credit card | First findings in minutes