GHSA-2p39-2jf3-fv2q: Infoleak
Impact
The HTTP route handler exported by next-video/request-handler — which the README instructs consumers to mount at /api/video — allows an unauthenticated remote attacker to read arbitrary .json files from the production filesystem of any application following the documented setup.
The handler's GET endpoint accepts a url query parameter and uses it to locate and serve a JSON asset descriptor from disk. The only guard between "remote URL" and "local file path" is a regex check for ^https?://. Any value that does not match that prefix is treated as a local path, .json is appended, and the file is read with fs.readFile and returned in the HTTP response — with no authentication, no path canonicalization, and no traversal guard.
On a typical Next.js deployment this exposes, at minimum: - The Next.js Server Actions AES encryption key (.next/server/server-reference-manifest.json) - The Next.js Preview/Draft Mode keys (previewModeId, previewModeSigningKey, previewModeEncryptionKey) - Internal build manifests, route registries, and absolute runtime paths - Application-specific asset metadata (e.g. Mux uploadId, assetId, playbackId values stored in videos/.json)
Any application that mounted /api/video following the documented one-liner is affected.
Patches
2.8.1
Workarounds
Until a patched version is available, wrap the exported handler in your own route file and validate the url parameter before passing it through:
- Reject any url value that does not begin with https://, or that does not match a known allowlist of trusted remote hosts. - Alternatively, remove the /api/video route entirely if your application only uses build-time import of local video files and does not use <Video src="https://..."> with string URLs at runtime.
References
- src/request-handler.ts — the vulnerable GET handler - src/assets.ts — getAssetPath(), where the local-vs-remote branching occurs - src/utils/utils.ts — isRemote(), the sole guard between the two branches - src/config.ts — loadAsset(), which performs the unconstrained fs.readFile
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/next-videoto a version that resolves this vulnerability.Fixed in 2.8.1 - Remove
Remove
next-video/request-handler (/api/video route)from your environment.Alternatively, remove the `/api/video` route entirely if your application only uses build-time `import` of local video files and does not use `<Video src="https://...">` with string URLs at runtime.
- Compensating control
Wrap the exported `next-video/request-handler` in your own route at `/api/video`, and validate the `url` query parameter before passing it through: reject any `url` value that does not begin with `https://`, and reject any value that does not match a known allowlist of trusted remote hosts.
Event History
Frequently Asked Questions
Which deployments are exposed?
Applications that mount the next-video/request-handler HTTP route as documented at /api/video are exposed if the endpoint is reachable by unauthenticated remote users. The documented setup makes the handler available without the path validation or authentication described in the advisory.
What does an attacker need to exploit this?
An attacker only needs unauthenticated HTTP access to the handler's GET endpoint and control of its url query parameter. Values not beginning with http:// or https:// are treated as local paths, have .json appended, and are read from the production filesystem.
What data could be disclosed?
The issue can expose arbitrary readable .json files, including the Next.js server-reference manifest containing the Server Actions AES encryption key and preview/draft mode keys. It may also reveal build manifests, route registries, absolute runtime paths, and application-specific asset metadata.
How can I identify whether an application is affected?
Review whether the application uses npm/next-video and mounts the request handler exported by next-video/request-handler, particularly at /api/video. Also review whether that route is accessible without authentication and whether it accepts the url query parameter.