CVE-2017-16877: Zeit Next.js

High severity, CVSS 7.5. EPSS: 14.1% chance of exploitation in the next 30 days.

ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.

Affected products

  • Zeit Next.js: before 2.4.1 (fixed in 2.4.1)

Published 2017-11-17. Last modified 2026-06-17.