QID 980506

QID 980506: Nodejs (npm) Security Update for next (GHSA-x56p-c8cg-q435)

Security update has been released for next to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

- **Affected**: Users of Next.js between 9.5.0 and 9.5.3
- **Not affected**: Deployments on Vercel ([https://vercel.com](https://vercel.com)) are not affected
- **Not affected**: Deployments using `next export`

We recommend everyone to upgrade regardless of whether you can reproduce the issue or not.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    https://github.com/vercel/next.js/releases/tag/v9.5.4
    Vendor References

    CVEs related to QID 980506

    Software Advisories
    Advisory ID Software Component Link
    GHSA-x56p-c8cg-q435 next URL Logo github.com/advisories/GHSA-x56p-c8cg-q435