QID 981453

QID 981453: Nodejs (npm) Security Update for next (GHSA-vxf5-wxwp-m7g9)

Security update has been released for next to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

- **Affected:** Users of Next.js between `10.0.5` and `10.2.0`
- **Affected:** Users of Next.js between `11.0.0` and `11.0.1` using `pages/_error.js` without `getInitialProps`
- **Affected:** Users of Next.js between `11.0.0` and `11.0.1` using `pages/_error.js` and `next export`
- **Not affected**: Deployments on Vercel ([vercel.com](https://vercel.com)) are not affected
- **Not affected:** Deployments **with** `pages/404.js`

We recommend everyone to upgrade regardless of whether you can reproduce the issue or not.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    https://github.com/vercel/next.js/releases/tag/v11.1.0
    Vendor References

    CVEs related to QID 981453

    Software Advisories
    Advisory ID Software Component Link
    GHSA-vxf5-wxwp-m7g9 next URL Logo github.com/advisories/GHSA-vxf5-wxwp-m7g9