You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Open Redirect in Next.js versions
Moderate severity
GitHub Reviewed
Published
Oct 8, 2020
in
vercel/next.js
•
Updated Jan 9, 2023
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
Learn more on MITRE.
Impact
next export
We recommend everyone to upgrade regardless of whether you can reproduce the issue or not.
Patches
https://github.com/vercel/next.js/releases/tag/v9.5.4
References
https://github.com/vercel/next.js/releases/tag/v9.5.4
References