VDB
Sign up
MEDIUM4.3

GHSA-xv57-4mr9-wg8v

Next.js Content Injection Vulnerability for Image Optimization

Quick fix

GHSA-xv57-4mr9-wg8v — next: upgrade to the fixed version with the command below.

npm install next@14.2.31

Details

A vulnerability in **Next.js Image Optimization** has been fixed in **v15.4.5** and **v14.2.31**. The issue allowed attacker-controlled external image sources to trigger file downloads with arbitrary content and filenames under specific configurations. This behavior could be abused for phishing or malicious file delivery.

All users relying on `images.domains` or `images.remotePatterns` are encouraged to upgrade and verify that external image sources are strictly validated.

More details at [Vercel Changelog](https://vercel.com/changelog/cve-2025-55173)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/next
Introduced in: 0.9.9Fixed in: 14.2.31
Fixnpm install next@14.2.31
npm/next
Introduced in: 15.0.0Fixed in: 15.4.5
Fixnpm install next@15.4.5

References