QSearchQSearch

CVE-2021-39178

7.5 HIGH

Next.js is a React framework

Published: 2021-08-31 · Last updated: 2026-06-17

Severity and scoring

CVSS
7.5 HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-79

Affected products

VendorProduct
vercelnext.js

Description

Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability. In order for an instance to be affected by the vulnerability, the `next.config.js` file must have `images.domains` array assigned and the image host assigned in `images.domains` must allow user-provided SVG. If the `next.config.js` file has `images.loader` assigned to something other than default or the instance is deployed on Vercel, the instance is not affected by the vulnerability. The vulnerability is patched in Next.js version 11.1.1.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-8769 A vulnerability was determined in vercel ai up to 3.0.97 (4.3 MEDIUM)
  • CVE-2026-8768 A vulnerability was found in vercel ai up to 3.0.97 (7.3 HIGH)
  • CVE-2026-8767 A vulnerability has been found in vercel ai up to 3.0.97 (5.0 MEDIUM)
  • CVE-2026-46508 Turborepo is a high-performance build system for JavaScript and TypeScript codebases (7.8 HIGH)
  • CVE-2026-45773 Turborepo is a high-performance build system for JavaScript and TypeScript codebases (6.5 MEDIUM)

Same CWE

  • CVE-2026-12425 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access ...
  • CVE-2024-30476 PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager (5.4 MEDIUM)
  • CVE-2026-54198 Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions (7.1 HIGH)
  • CVE-2026-54191 Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions (7.1 HIGH)
  • CVE-2026-39437 Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions (7.1 HIGH)