ZERO
Back
vulnerabilityCVE-2026-94486

CVE-2026-94486

A flaw was found in Next.js. The local development server exposes a Model Context Protocol (MCP) endpoint without properly restricting cross-site requests. If a developer running the development server visits a malicious website, an attacker can issue unauthorized requests to this endpoint, leading to sensitive information disclosure. This flaw allows unauthorized access to local project file locations, source code snippets from error reports, application route inventories, and development logs.

Exploitation evidence
None confirmed

Affected software

CVSS (Common Vulnerability Scoring System)

Preferred assessment

Vector

Attack vector

Attack complexity

Privileges required

User interaction

Scope

Confidentiality impact

Integrity impact

Availability impact

Source assessments

EPSS (Exploit Prediction Scoring System)

Probability

Percentile

Model

Preferred remediation

Action