Improper access control in Next.js - CVE-2026-94485
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in App Router metadata image routes when requesting metadata image URLs for dynamic segments deliberately excluded from generateStaticParams(). A remote attacker can request a metadata image URL for an excluded dynamic segment to disclose sensitive information.
The issue affects applications built with webpack.