vulnerabilityCVE-2026-94486
CVE-2026-94486
A flaw was found in Next.js. The local development server exposes a Model Context Protocol (MCP) endpoint without properly restricting cross-site requests. If a developer running the development server visits a malicious website, an attacker can issue unauthorized requests to this endpoint, leading to sensitive information disclosure. This flaw allows unauthorized access to local project file locations, source code snippets from error reports, application route inventories, and development logs.
Exploitation evidence
None confirmed
Affected software
| Software | Affected versions | Fixed in | Sources |
|---|---|---|---|
CVSS (Common Vulnerability Scoring System)
Preferred assessment
Vector
Attack vector
Attack complexity
Privileges required
User interaction
Scope
Confidentiality impact
Integrity impact
Availability impact
Source assessments
EPSS (Exploit Prediction Scoring System)
Probability
Percentile
Model
Preferred remediation
Action