VDB
Sign up
MEDIUM6.1

GHSA-gx5p-jg67-6x7h

Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

Quick fix

GHSA-gx5p-jg67-6x7h — next: upgrade to the fixed version with the command below.

npm install next@15.5.16

Details

### Impact

Applications that use `beforeInteractive` scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser.

### Fix

We now HTML-escape serialized `beforeInteractive` script content before embedding it into the page, preventing attacker-controlled content from breaking out of the inline script boundary.

### Workarounds

If you cannot upgrade immediately, do not pass untrusted data into `beforeInteractive` scripts. If that pattern is unavoidable, sanitize or escape the content before embedding it.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/next
Introduced in: 13.0.0Fixed in: 15.5.16
Fixnpm install next@15.5.16
npm/next
Introduced in: 16.0.0Fixed in: 16.2.5
Fixnpm install next@16.2.5

References