CVE-2025-13984: Next.js - Critical - Access bypass - SA-CONTRIB-2025-122
Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13984?
CVE-2025-13984 is classified as a critical vulnerability due to its potential for access bypass and enabling XSS attacks.
How do I fix CVE-2025-13984?
To mitigate CVE-2025-13984, upgrade Next.js to version 1.6.4 or later, or version 2.0.1 or later.
What types of applications are affected by CVE-2025-13984?
CVE-2025-13984 affects Next.js applications using versions prior to 1.6.4 and 2.0.1.
What is the impact of CVE-2025-13984 on my application?
The impact of CVE-2025-13984 includes exposing your application to XSS vulnerabilities through a permissive cross-domain policy.
Is CVE-2025-13984 related to Drupal?
Yes, CVE-2025-13984 stems from a vulnerability in the Drupal Next.js integration that allows cross-site scripting.