CVE-2026-54150: Infoleak

Published Aug 20, 2026
·
Updated

Impact

The HTTP route handler exported by next-video/request-handler — which the README instructs consumers to mount at /api/video — allows an unauthenticated remote attacker to read arbitrary .json files from the production filesystem of any application following the documented setup.

The handler's GET endpoint accepts a url query parameter and uses it to locate and serve a JSON asset descriptor from disk. The only guard between "remote URL" and "local file path" is a regex check for ^https?://. Any value that does not match that prefix is treated as a local path, .json is appended, and the file is read with fs.readFile and returned in the HTTP response — with no authentication, no path canonicalization, and no traversal guard.

On a typical Next.js deployment this exposes, at minimum: - The Next.js Server Actions AES encryption key (.next/server/server-reference-manifest.json) - The Next.js Preview/Draft Mode keys (previewModeId, previewModeSigningKey, previewModeEncryptionKey) - Internal build manifests, route registries, and absolute runtime paths - Application-specific asset metadata (e.g. Mux uploadId, assetId, playbackId values stored in videos/.json)

Any application that mounted /api/video following the documented one-liner is affected.

Patches

2.8.1

Workarounds

Until a patched version is available, wrap the exported handler in your own route file and validate the url parameter before passing it through:

- Reject any url value that does not begin with https://, or that does not match a known allowlist of trusted remote hosts. - Alternatively, remove the /api/video route entirely if your application only uses build-time import of local video files and does not use <Video src="https://..."> with string URLs at runtime.

References

- src/request-handler.ts — the vulnerable GET handler - src/assets.ts — getAssetPath(), where the local-vs-remote branching occurs - src/utils/utils.ts — isRemote(), the sole guard between the two branches - src/config.ts — loadAsset(), which performs the unconstrained fs.readFile

Affected Software

1 affected componentFixes available
npm/next-video<=2.8.0
2.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/next-video to a version that resolves this vulnerability.

    Fixed in 2.8.1
  2. Remove

    Remove /api/video route (exported handler from next-video/request-handler) from your environment.

    If the application only uses build-time `import` of local video files and does not use `<Video src="https://...">` with string URLs at runtime, remove the `/api/video` route entirely.

  3. Configuration

    Until a patched version is available, do not pass the request through unvalidated. Instead, wrap the exported handler and, before calling it, validate the GET query parameter `url`: (1) it must begin with `https://` (not `http://`), and (2) it must match a known allowlist of trusted remote hosts. Reject any other `url` values.

    Application route wrapper around next-video/request-handler (mounted at /api/video) url query parameter validation = Reject any url that does not begin with https:// and reject values that do not match a known allowlist of trusted remote hosts

Event History

Aug 20, 2026
Advisory Published
via GitHub·06:35 PM
Data Sourced
via GitHub·06:35 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed?

Applications using npm/next-video that mount the next-video/request-handler route as documented at /api/video are exposed. The issue affects production deployments where the handler can access the application filesystem.

2

Does exploitation require authentication or a privileged account?

No. An unauthenticated remote attacker can use the handler's GET endpoint and supply a url parameter that does not begin with http:// or https://, causing it to be handled as a local path.

3

What information could be disclosed?

The handler can return arbitrary .json files readable by the production process. Listed examples include the Next.js Server Actions AES encryption key, Preview/Draft Mode keys, build manifests, route registries, absolute runtime paths, and application asset metadata.

4

How can I determine whether my deployment is affected?

Check whether your application exposes next-video/request-handler, particularly at the documented /api/video route, and whether its GET endpoint is reachable without authentication. Also determine whether the application process can read sensitive JSON files such as .next/server/server-reference-manifest.json.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203