Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, origin: null was treated as a "missing" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a victim browser to submit Server Actions from a sandboxed context, potentially executing state-changing actions with victim credentials (CSRF). This is fixed in version 16.1.7 by treating 'null' as an explicit origin value and enforcing host/origin checks unless 'null' is explicitly allowlisted in experimental.serverActions.allowedOrigins. If upgrading is not immediately possible, add CSRF tokens for sensitive Server Actions, prefer SameSite=Strict on sensitive auth cookies, and/or do not allow 'null' in serverActions.allowedOrigins unless intentionally required and additionally protected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a multi-PoC lab for three Next.js vulnerabilities, not a single offensive implant or framework module. Structure is cleanly split into pocs/ for vulnerable demo apps and scripts/ for reproduction drivers, with docker-compose.yml orchestrating vulnerable and fixed side-by-side containers. Languages are primarily JavaScript/Node.js with Docker and YAML support files. CVE-2025-29927 PoC: a minimal Next.js app protects /dashboard only via middleware in pocs/cve-2025-29927/middleware.js. The exploit script scripts/run-cve-2025-29927.mjs sends a normal request and then a second request with attacker-controlled x-middleware-subrequest set to repeated middleware names. On vulnerable versions, this causes middleware recursion-depth logic to be treated as already exhausted, skipping middleware execution and exposing the protected dashboard. Capability: authorization bypass. CVE-2026-27978 PoC: the app in pocs/cve-2026-27978 exposes a Server Action transferFunds that records a transfer if a session cookie exists. The helper endpoints /api/login, /api/reset, and /api/state support setup and observation. The exploit script scripts/run-cve-2026-27978.mjs obtains a victim session cookie from /api/login, fetches the page to parse the generated $ACTION_* field, then submits the form with Cookie plus Origin: null. On vulnerable versions, the Server Action executes and mutates state. Capability: CSRF-style state-changing action execution under a victim session. CVE-2026-29057 PoC: the app in pocs/cve-2026-29057 rewrites /rewrites/* to an external intermediary at http://127.0.0.1:4000. support/server.js launches three components: Next.js on port 3000, an intermediary proxy on 4000, and a backend on 5000 that records requests into /tmp/cve-2026-29057-state.json. The exploit script scripts/run-cve-2026-29057.mjs uses raw TCP via node:net to send a crafted chunked DELETE /rewrites/poc containing a smuggled GET /secret. On vulnerable versions, both requests are observed by the backend. Capability: HTTP request smuggling through rewrite/proxy behavior. Overall purpose: provide reproducible, side-by-side vulnerable/fixed environments to validate and study three Next.js security issues. The repository is a legitimate proof-of-concept suite with active exploit logic, not merely documentation or passive detection.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.