Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.
References
History

Thu, 29 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal next.js
Vendors & Products Drupal
Drupal next.js

Wed, 28 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Description Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.
Title Next.js - Critical - Access bypass - SA-CONTRIB-2025-122
Weaknesses CWE-942
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published: 2026-01-28T20:02:22.486Z

Updated: 2026-01-29T18:24:28.956Z

Reserved: 2025-12-03T17:04:25.507Z

Link: CVE-2025-13984

cve-icon Vulnrichment

Updated: 2026-01-29T18:24:21.845Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-28T20:16:07.807

Modified: 2026-01-29T19:16:10.677

Link: CVE-2025-13984

cve-icon Redhat

No data.