Next.js 16's next dev MCP endpoint skipped origin checks, letting a visited site read disk paths, source snippets, routes and logs. Low severity; fixed in 16.3.8.
Vercel has fixed a low-severity flaw in the Next.js development server. Since Next.js 16, next dev exposes a Model Context Protocol (MCP) endpoint, and that endpoint did not check which website a request came from. A malicious page open in the developer's browser could read the project's location on disk, source code snippets from error reports, the route inventory and development logs. Versions 16.0.0 up to but not including 16.3.8 are affected. The flaw is in next dev only, and production deployments do not serve the endpoint. Upgrading to 16.3.8 fixes it.
A note on identifiers. Vercel's advisory tracks the MCP flaw as CVE-2026-94486 (GHSA-39w2-rjm5-chcv), rated Low at CVSS 4.0 2.3. The adjacent CVE-2026-94485 (GHSA-f87g-xv8r-7p7x) is a different bug: metadata image routes in webpack-built App Router apps ignore dynamicParams. It is rated Medium at 6.3. As of 3 October, the NVD and CVE.org records for CVE-2026-94485 carry the MCP description text, so scanners and feeds may attach the MCP description, and the 6.3 score, to it. See "What is still unclear".
What happened
Next.js 16.3.8 was released on 30 September 2026 with fixes for seven security advisories: one High (server-side request forgery in Image Optimization), five Medium and one Low. The Low advisory is the MCP issue. The CVE records were published on 2 October.
According to Vercel's advisory, the development server "exposes a Model Context Protocol endpoint that does not verify which website a request originates from". A website the developer visits can therefore pull development data from the local server.
Why it matters
This is information disclosure on a developer workstation. It is not remote code execution and not a production exposure. The advisory lists four kinds of data at risk:
- the project's location on disk
- source code snippets from error reports
- the route inventory
- development logs
That is useful reconnaissance. Source snippets and logs can also hold sensitive material, such as internal hostnames, or credentials that were logged by mistake. The advisory describes read access only.
The MCP server is on by default. The Next.js source at v16.3.8 documents the experimental.mcpServer option as @default true and exposes the server at /_next/mcp, so developers did not opt in. The Next.js documentation presents the endpoint as support for AI coding agents through the next-devtools-mcp package.
There is no sign of exploitation. Neither CVE is in CISA's Known Exploited Vulnerabilities catalog (version 2026.10.02). The SSVC assessment attached to the NVD record lists exploitation "none" and automatable "no". We found no public proof of concept in the sources we read.
Technical details
- Affected:
next>= 16.0.0 and < 16.3.8, when run withnext dev. Fixed: 16.3.8. - Weakness: CWE-346 (origin validation error), per NVD.
- CVSS 4.0 (CVE-2026-94486):
AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N, score 2.3 (Low), from GitHub as the CNA.AT:Pmeans "attack requirements present" andUI:Pmeans passive user interaction. The advisory does not spell either out. From its text, the attack needs a runningnext devserver and a developer who visits a hostile page in a browser that can reach it. That reading is ours, not Vercel's. - The fix: commit
2d9f50a, titled "Fix MCP middleware DNS rebinding", changes two files. The cross-site check for internal dev endpoints (block-cross-site-dev.ts) now matches on a parsed URL pathname instead of a substring of the raw request URL. The MCP middleware now matches/_next/mcpexactly, ignoring a trailing slash, instead of by prefix. Vercel has not described the bypass. The commit title points to DNS rebinding as the attack class, but the advisory does not use the term, so treat it as likely, not confirmed.
Before Next.js 16.3.8, a web page the developer visited while next dev was running could read project data from the /_next/mcp endpoint. Production deployments are not affected.
We are not publishing exploit details.
What defenders should do
- Upgrade
nextto 16.3.8 or later in every project on the 16.x line, including lockfiles, templates and shared dev containers. The same release fixes a High SSRF in Image Optimization and several Medium cache issues that affect production, so the upgrade is worth doing for those alone. - Until you upgrade, keep
next devand untrusted browsing apart. This is general hygiene, not a workaround from the vendor. Neither advisory offers a workaround. - Consider turning the MCP server off where nobody uses it. The documented setting is
experimental.mcpServer: falseinnext.config. We have not tested whether it blocks this issue on unpatched versions, and Vercel does not offer it as a mitigation. - Treat dev logs and error output as sensitive. Keep secrets out of them, on the assumption that dev-server data can leak.
- Check your scanner's output. If a tool flags CVE-2026-94485 with the MCP description, check the advisory ID. GHSA-f87g-xv8r-7p7x, the metadata-image bug, is a separate issue in webpack-built App Router apps and needs its own assessment. The 16.3.8 upgrade fixes both.
For earlier Next.js risk, see our coverage of CVE-2026-23870, the React Server Components DoS in the App Router.
What is still unclear
- The CVE record mix-up. Vercel's advisory API and the CVE.org titles map the MCP flaw to CVE-2026-94486 and the metadata-image bug to CVE-2026-94485. The description text on both NVD records, and on CVE.org for CVE-2026-94485, is the MCP text. Both NVD records are "Awaiting Analysis". We don't yet know when the CVE-2026-94485 description will be corrected.
- The exact bypass. Vercel has not explained how the cross-site check failed.
- Interim mitigations. It is unconfirmed whether
allowedDevOriginsor disablingmcpServercloses the issue on unpatched versions. - Credit. The advisories list no reporter.
- The patched-version field. The advisories' patched-version field reads "16.3.?". The 16.3.8 fix version comes from the CVE text and the release notes.
Sources
- GitHub advisory GHSA-39w2-rjm5-chcv (MCP endpoint, CVE-2026-94486)
- GitHub advisory GHSA-f87g-xv8r-7p7x (metadata image routes, CVE-2026-94485)
- NVD: CVE-2026-94486
- NVD: CVE-2026-94485
- CVE.org: CVE-2026-94485
- Next.js v16.3.8 release notes
- Fix commit 2d9f50a
- Next.js config source at v16.3.8 (
mcpServerdefault) - Next.js guide: MCP
- CISA Known Exploited Vulnerabilities catalog