Description
Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.
Problem types
CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains
Product status
0.0.0 (semver) before 1.6.4
2.0.0 (semver) before 2.0.1
Credits
Mike Decker (pookmish)
Brian Perry (brianperry)
Rob Decker (rrrob)
Bram Driesen (bramdriesen)
Greg Knaddison (greggles)
Jess (xjm)
References
www.drupal.org/sa-contrib-2025-122