CVE-2021-39178
7.5 HIGHNext.js is a React framework
Published: 2021-08-31 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 7.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-79
Affected products
| Vendor | Product |
|---|---|
| vercel | next.js |
Description
Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability. In order for an instance to be affected by the vulnerability, the `next.config.js` file must have `images.domains` array assigned and the image host assigned in `images.domains` must allow user-provided SVG. If the `next.config.js` file has `images.loader` assigned to something other than default or the instance is deployed on Vercel, the instance is not affected by the vulnerability. The vulnerability is patched in Next.js version 11.1.1.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-39178
- [Patch]https://github.com/vercel/next.js/releases/tag/v11.1.1
- [Patch]https://github.com/vercel/next.js/security/advisories/GHSA-9gr3-7897-pp7m
- [Patch]https://github.com/vercel/next.js/releases/tag/v11.1.1
- [Patch]https://github.com/vercel/next.js/security/advisories/GHSA-9gr3-7897-pp7m
Related CVEs
Same vendor
- CVE-2026-8769 — A vulnerability was determined in vercel ai up to 3.0.97 (4.3 MEDIUM)
- CVE-2026-8768 — A vulnerability was found in vercel ai up to 3.0.97 (7.3 HIGH)
- CVE-2026-8767 — A vulnerability has been found in vercel ai up to 3.0.97 (5.0 MEDIUM)
- CVE-2026-46508 — Turborepo is a high-performance build system for JavaScript and TypeScript codebases (7.8 HIGH)
- CVE-2026-45773 — Turborepo is a high-performance build system for JavaScript and TypeScript codebases (6.5 MEDIUM)
Same CWE
- CVE-2026-12425 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access ...
- CVE-2024-30476 — PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager (5.4 MEDIUM)
- CVE-2026-54198 — Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions (7.1 HIGH)
- CVE-2026-54191 — Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions (7.1 HIGH)
- CVE-2026-39437 — Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions (7.1 HIGH)