GHSA-2p39-2jf3-fv2q: Infoleak

Published Aug 20, 2026
·
Updated

Impact

The HTTP route handler exported by next-video/request-handler — which the README instructs consumers to mount at /api/video — allows an unauthenticated remote attacker to read arbitrary .json files from the production filesystem of any application following the documented setup.

The handler's GET endpoint accepts a url query parameter and uses it to locate and serve a JSON asset descriptor from disk. The only guard between "remote URL" and "local file path" is a regex check for ^https?://. Any value that does not match that prefix is treated as a local path, .json is appended, and the file is read with fs.readFile and returned in the HTTP response — with no authentication, no path canonicalization, and no traversal guard.

On a typical Next.js deployment this exposes, at minimum: - The Next.js Server Actions AES encryption key (.next/server/server-reference-manifest.json) - The Next.js Preview/Draft Mode keys (previewModeId, previewModeSigningKey, previewModeEncryptionKey) - Internal build manifests, route registries, and absolute runtime paths - Application-specific asset metadata (e.g. Mux uploadId, assetId, playbackId values stored in videos/.json)

Any application that mounted /api/video following the documented one-liner is affected.

Patches

2.8.1

Workarounds

Until a patched version is available, wrap the exported handler in your own route file and validate the url parameter before passing it through:

- Reject any url value that does not begin with https://, or that does not match a known allowlist of trusted remote hosts. - Alternatively, remove the /api/video route entirely if your application only uses build-time import of local video files and does not use <Video src="https://..."> with string URLs at runtime.

References

- src/request-handler.ts — the vulnerable GET handler - src/assets.ts — getAssetPath(), where the local-vs-remote branching occurs - src/utils/utils.ts — isRemote(), the sole guard between the two branches - src/config.ts — loadAsset(), which performs the unconstrained fs.readFile

Affected Software

1 affected componentFixes available
npm/next-video<=2.8.0
2.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/next-video to a version that resolves this vulnerability.

    Fixed in 2.8.1
  2. Remove

    Remove next-video/request-handler (/api/video route) from your environment.

    Alternatively, remove the `/api/video` route entirely if your application only uses build-time `import` of local video files and does not use `<Video src="https://...">` with string URLs at runtime.

  3. Compensating control

    Wrap the exported `next-video/request-handler` in your own route at `/api/video`, and validate the `url` query parameter before passing it through: reject any `url` value that does not begin with `https://`, and reject any value that does not match a known allowlist of trusted remote hosts.

Event History

Aug 20, 2026
Advisory Published
via GitHub·06:35 PM
Data Sourced
via GitHub·06:35 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Applications that mount the next-video/request-handler HTTP route as documented at /api/video are exposed if the endpoint is reachable by unauthenticated remote users. The documented setup makes the handler available without the path validation or authentication described in the advisory.

2

What does an attacker need to exploit this?

An attacker only needs unauthenticated HTTP access to the handler's GET endpoint and control of its url query parameter. Values not beginning with http:// or https:// are treated as local paths, have .json appended, and are read from the production filesystem.

3

What data could be disclosed?

The issue can expose arbitrary readable .json files, including the Next.js server-reference manifest containing the Server Actions AES encryption key and preview/draft mode keys. It may also reveal build manifests, route registries, absolute runtime paths, and application-specific asset metadata.

4

How can I identify whether an application is affected?

Review whether the application uses npm/next-video and mounts the request handler exported by next-video/request-handler, particularly at /api/video. Also review whether that route is accessible without authentication and whether it accepts the url query parameter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203