Missing Origin Validation in WebSockets Affecting next package, versions >=13.0.0 <15.2.2


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-NEXT-10259370
  • published29 May 2025
  • disclosed28 May 2025
  • creditsapphi-red, Radman Siddiki

Introduced: 28 May 2025

NewCVE-2025-48068  (opens in a new tab)
CWE-1385  (opens in a new tab)

How to fix?

Upgrade next to version 15.2.2 or higher.

Overview

next is a react framework.

Affected versions of this package are vulnerable to Missing Origin Validation in WebSockets when running next dev and the project uses the App Router. An attacker can access the source code of client components by exploiting the Cross-site WebSocket hijacking (CSWSH) attack when a user visits a malicious link while having the server running locally.

Workarounds

  1. Avoid browsing untrusted websites while running the local development server.

  2. Implement local firewall or proxy rules to block unauthorized WebSocket access to localhost.

CVSS Base Scores

version 4.0
version 3.1