watch Cve 2026 94486 · Exploits

Next.js Dev Server MCP Flaw CVE-2026-94486 Lets Malicious Sites Read Source Snippets and Logs

Data graphic: Next.js dev server MCP flaw CVE-2026-94486, rated CVSS 4.0 2.3 Low, with a FIXED stamp; fixed in Next.js 16.3.8, with no exploitation reported.
SH

Vulnerability analyst · Updated Oct 2, 2026, 4:54 PM EDT

Next.js 16's next dev MCP endpoint skipped origin checks, letting a visited site read disk paths, source snippets, routes and logs. Low severity; fixed in 16.3.8.

Vercel has fixed a low-severity flaw in the Next.js development server. Since Next.js 16, next dev exposes a Model Context Protocol (MCP) endpoint, and that endpoint did not check which website a request came from. A malicious page open in the developer's browser could read the project's location on disk, source code snippets from error reports, the route inventory and development logs. Versions 16.0.0 up to but not including 16.3.8 are affected. The flaw is in next dev only, and production deployments do not serve the endpoint. Upgrading to 16.3.8 fixes it.

A note on identifiers. Vercel's advisory tracks the MCP flaw as CVE-2026-94486 (GHSA-39w2-rjm5-chcv), rated Low at CVSS 4.0 2.3. The adjacent CVE-2026-94485 (GHSA-f87g-xv8r-7p7x) is a different bug: metadata image routes in webpack-built App Router apps ignore dynamicParams. It is rated Medium at 6.3. As of 3 October, the NVD and CVE.org records for CVE-2026-94485 carry the MCP description text, so scanners and feeds may attach the MCP description, and the 6.3 score, to it. See "What is still unclear".

What happened

Next.js 16.3.8 was released on 30 September 2026 with fixes for seven security advisories: one High (server-side request forgery in Image Optimization), five Medium and one Low. The Low advisory is the MCP issue. The CVE records were published on 2 October.

According to Vercel's advisory, the development server "exposes a Model Context Protocol endpoint that does not verify which website a request originates from". A website the developer visits can therefore pull development data from the local server.

Why it matters

This is information disclosure on a developer workstation. It is not remote code execution and not a production exposure. The advisory lists four kinds of data at risk:

  • the project's location on disk
  • source code snippets from error reports
  • the route inventory
  • development logs

That is useful reconnaissance. Source snippets and logs can also hold sensitive material, such as internal hostnames, or credentials that were logged by mistake. The advisory describes read access only.

The MCP server is on by default. The Next.js source at v16.3.8 documents the experimental.mcpServer option as @default true and exposes the server at /_next/mcp, so developers did not opt in. The Next.js documentation presents the endpoint as support for AI coding agents through the next-devtools-mcp package.

There is no sign of exploitation. Neither CVE is in CISA's Known Exploited Vulnerabilities catalog (version 2026.10.02). The SSVC assessment attached to the NVD record lists exploitation "none" and automatable "no". We found no public proof of concept in the sources we read.

Technical details

  • Affected: next >= 16.0.0 and < 16.3.8, when run with next dev. Fixed: 16.3.8.
  • Weakness: CWE-346 (origin validation error), per NVD.
  • CVSS 4.0 (CVE-2026-94486): AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N, score 2.3 (Low), from GitHub as the CNA. AT:P means "attack requirements present" and UI:P means passive user interaction. The advisory does not spell either out. From its text, the attack needs a running next dev server and a developer who visits a hostile page in a browser that can reach it. That reading is ours, not Vercel's.
  • The fix: commit 2d9f50a, titled "Fix MCP middleware DNS rebinding", changes two files. The cross-site check for internal dev endpoints (block-cross-site-dev.ts) now matches on a parsed URL pathname instead of a substring of the raw request URL. The MCP middleware now matches /_next/mcp exactly, ignoring a trailing slash, instead of by prefix. Vercel has not described the bypass. The commit title points to DNS rebinding as the attack class, but the advisory does not use the term, so treat it as likely, not confirmed.

Data graphic: How Next.js CVE-2026-94486 works: a malicious website, visited in the developer's browser, reaches the next dev endpoint at /_next/mcp, which before 16.3.8 did not check request origin, and reads the project location on disk, source snippets from error reports, the route inventory and development logs. Rated Low CVSS 4.0 2.3 , development server only.

Before Next.js 16.3.8, a web page the developer visited while next dev was running could read project data from the /_next/mcp endpoint. Production deployments are not affected.

We are not publishing exploit details.

What defenders should do

  1. Upgrade next to 16.3.8 or later in every project on the 16.x line, including lockfiles, templates and shared dev containers. The same release fixes a High SSRF in Image Optimization and several Medium cache issues that affect production, so the upgrade is worth doing for those alone.
  2. Until you upgrade, keep next dev and untrusted browsing apart. This is general hygiene, not a workaround from the vendor. Neither advisory offers a workaround.
  3. Consider turning the MCP server off where nobody uses it. The documented setting is experimental.mcpServer: false in next.config. We have not tested whether it blocks this issue on unpatched versions, and Vercel does not offer it as a mitigation.
  4. Treat dev logs and error output as sensitive. Keep secrets out of them, on the assumption that dev-server data can leak.
  5. Check your scanner's output. If a tool flags CVE-2026-94485 with the MCP description, check the advisory ID. GHSA-f87g-xv8r-7p7x, the metadata-image bug, is a separate issue in webpack-built App Router apps and needs its own assessment. The 16.3.8 upgrade fixes both.

For earlier Next.js risk, see our coverage of CVE-2026-23870, the React Server Components DoS in the App Router.

What is still unclear

  • The CVE record mix-up. Vercel's advisory API and the CVE.org titles map the MCP flaw to CVE-2026-94486 and the metadata-image bug to CVE-2026-94485. The description text on both NVD records, and on CVE.org for CVE-2026-94485, is the MCP text. Both NVD records are "Awaiting Analysis". We don't yet know when the CVE-2026-94485 description will be corrected.
  • The exact bypass. Vercel has not explained how the cross-site check failed.
  • Interim mitigations. It is unconfirmed whether allowedDevOrigins or disabling mcpServer closes the issue on unpatched versions.
  • Credit. The advisories list no reporter.
  • The patched-version field. The advisories' patched-version field reads "16.3.?". The 16.3.8 fix version comes from the CVE text and the release notes.

Sources

Keep reading

All latest →
  1. criticalExploitsShinyHunters Exploits Oracle PeopleSoft CVE-2026-35273 via WAF Bypass5 min
  2. highExploitsZyxel GS1900 switch overflow exploited on 996 devices, now in CISA KEV4 min
  3. highExploitsMicrosoft SharePoint CVE-2026-65660 Added to CISA KEV After Rescore to RCE5 min
  4. criticalExploitsWSO2 API Manager JWT Bypass Exploited 133 Days After the Fix5 min
  5. criticalExploitsF5 BIG-IP APM: An Oversized Bearer Token Is Enough for Unauthenticated RCE6 min
  6. highExploitsApple Patches CoreGraphics Zero-Day Used Against Targeted iPhone Users5 min