Origin validation error in Next.js - CVE-2026-94486
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive development data.
The vulnerability exists due to improper origin validation in the Model Context Protocol endpoint when handling requests from websites. A remote attacker can trick the developer into visiting a malicious website to disclose sensitive development data.
Only applications running with the development server are affected; production deployments do not serve this endpoint.