#VU119127 Origin validation error in Next.js - CVE-2025-13984
Published: December 4, 2025
Next.js
rrrob
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. A remote attacker can make cross-origin requests to the site without administrator knowledge or consent.