Input validation error in Next.js - CVE-2025-55173

 

Input validation error in Next.js - CVE-2025-55173

Published: August 30, 2025


Vulnerability identifier: #VU114573
CSH Severity: Low
CVSS v4 BT: 1.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-55173
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient validation of user-supplied input within the Image Optimization feature. A remote attacker with control over external image sources can trigger file downloads with arbitrary content and filenames under specific configurations and perform phishing attacks.


Affected software

Next.js
IBM Security QRadar Network Threat Analytics
QRadar Pre-Validation App
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
WatsonX BI Assistant
Maximo Application Suite - Edge Data Collector
User Entity Behavior Analytics
InfoSphere Optim Archive Viewer
IBM Cloud Pak for Security
QRadar Suite
IBM Security QRadar Analyst Workflow

How to mitigate CVE-2025-55173

Install updates from vendor's website.

Next.js - addressed in versions 14.2.31, 15.4.5
IBM Security QRadar Network Threat Analytics - update to 1.4.2
IBM Cloud Pak for Security - update to 1.11.9.0
QRadar Pre-Validation App - update to 2.0.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.2
WatsonX BI Assistant - update to 5.2.2
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.21, 9.0.13, 9.1.3
QRadar Suite - update to 1.11.9.0
IBM Security QRadar Analyst Workflow - update to 3.0.1
User Entity Behavior Analytics - update to 5.0.2
InfoSphere Optim Archive Viewer - update to 11.7.0.14

External References

Related Security Bulletins