← Back to CVE List

CVE-2020-5284

Published: 2020-03-30T22:15Z
Last Modified: 2024-11-21T05:33Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. This issue is fixed in version 9.3.2. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt