OSV 1.4.0 · github-reviewed · 修改于 2026-08-21 02:35
发布时间
2026-08-21 02:35
GitHub 审查时间
2026-08-21 02:35
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/08/GHSA-2p39-2jf3-fv2q/GHSA-2p39-2jf3-fv2q.json
The HTTP route handler exported by next-video/request-handler — which the README instructs consumers to mount at /api/video — allows an unauthenticated remote attacker to read arbitrary .json files from the production filesystem of any application following the documented setup.
The handler's GET endpoint accepts a url query parameter and uses it to locate and serve a JSON asset descriptor from disk. The only guard between "remote URL" and "local file path" is a regex check for ^https?://. Any value that does not match that prefix is treated as a local path, .json is appended, and the file is read with fs.readFile and returned in the HTTP response — with no authentication, no path canonicalization, and no traversal guard.
On a typical Next.js deployment this exposes, at minimum:
.next/server/server-reference-manifest.json)previewModeId, previewModeSigningKey, previewModeEncryptionKey)uploadId, assetId, playbackId values stored in videos/*.json)Any application that mounted /api/video following the documented one-liner is affected.
2.8.1
Until a patched version is available, wrap the exported handler in your own route file and validate the url parameter before passing it through:
url value that does not begin with https://, or that does not match a known allowlist of trusted remote hosts./api/video route entirely if your application only uses build-time import of local video files and does not use with string URLs at runtime.<Video src="https://...">src/request-handler.ts — the vulnerable GET handlersrc/assets.ts — getAssetPath(), where the local-vs-remote branching occurssrc/utils/utils.ts — isRemote(), the sole guard between the two branchessrc/config.ts — loadAsset(), which performs the unconstrained fs.readFile