Security: CVE-2025-48068 – Origin validation in Next.js dev server
A low-severity vulnerability in the Next.js development server lacked proper origin validation, allowing malicious websites to initiate WebSocket hijacking and cross-origin script injection attacks. This has been fixed with an opt-in origin check configuration in patched versions 14.2.30 and 15.2.2, with the feature set to become default in a future major release.
A low-severity vulnerability in the Next.js dev server has been addressed.
This vulnerability affects Next.js versions through and through . It includes two related issues affecting the local development server: and . Both stem from the lack of origin validation on development server resources.13.0.014.2.2915.0.015.2.1Cross-Site WebSocket Hijacking (CSWSH)Cross-Origin Script Inclusion
When running , a malicious website can:next dev
The root cause is insufficient origin verification on local development server resources, including the WebSocket server and static script endpoints. This issue is similar to , though scoped strictly to local development use.CVE-2018-14732
This issue was fixed in These releases introduce a configuration option to enable origin checks, which help prevent unauthorized cross-origin requests to the local development server. You can learn how to enable this option after upgrading to a patched version by visiting our . Note that this configuration is currently opt-in and will become the default in a future major release. Next.js versions and .14.2.3015.2.2documentation page
This CVE affects local development, no mitigation are required for applications in production on Vercel.
Thanks to and for responsibly disclosing this issue.sapphi-redRadman Siddiki
Summary
Impact
Resolution
Workarounds
For Vercel Customers
Credit
References
to and interact with the local development server if the project uses the App Router, potentially exposing internal component code.Initiate a WebSocket connection
localhostreferencing predictable paths for development scripts (e.g., ), which are then executed in the attacker's origin. This can allow extraction of source codeInject a
<script>tag/app/page.js
Avoid browsing untrusted websites while running the local development server
Implement local firewall or proxy rules to block unauthorized access to the development server
Source: original entry ↗
More from Vercel
Follow Vercel to get its new changes in your feed and email digest.
OpenAI Decisions API now available on AI Gateway
OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.
Timestamp attributes now supported in Vercel Flags
Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.
Glyph Cluster now available in stealth on AI Gateway
Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.