{"id":"GHSA-5vj8-3v2h-h38v","aliases":[],"url":"https://o3.security/vulnerability/GHSA-5vj8-3v2h-h38v","summary":"Remote Code Execution in next","details":"Versions of `next` prior to 5.1.0 are vulnerable to Remote Code Execution. The `/path:` route fails to properly sanitize input and passes it to a `require()` call. This allows attackers to execute JavaScript code on the server. Note that prior version 0.9.9 package `next` npm package hosted a different utility (0.4.1 being the latest version of that codebase), and this advisory does not apply to those versions.\n\n## Recommendation\n\nUpgrade to version 5.1.0.","published":"2020-09-04T18:04:08Z","modified":"2022-04-28T19:57:43Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"next","fixedVersion":"5.1.0"}],"fix":null,"references":[{"type":"PACKAGE","url":"https://github.com/vercel/next.js"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1538"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-04-28T19:57:43Z"}}