CVE-2025-48068
A low-severity vulnerability in the Next.js dev server has been addressed. This vulnerability affects Next.js versions through and through . It includes two related issues affecting the local development server: and . Both stem from the lack of origin validation on development server resources.13.0.014.2.2915.0.015.2.1Cross-Site WebSocket Hijacking (CSWSH)Cross-Origin Script Inclusion When running , a malicious website can:next dev The root cause is insufficient origin verification on local
