S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 23, 2024

CVE-2018-6184 Scanner

CVE-2018-6184 scanner - Local File Inclusion (LFI) vulnerability in Zeit Next.js

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
4
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-6184
7.5
CVSS

ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

ZEIT Next.js is a popular open-source framework for building React applications. It provides advanced features such as server-side rendering, automatic code splitting, and static site generation. Developed by ZEIT, Next.js is used by developers and companies to create high-performance web applications with minimal configuration. With Next.js, developers can focus on building their applications instead of worrying about complex build setups.

However, like any other software, Next.js is not immune to security vulnerabilities. An important vulnerability was detected in versions before 4.2.3. The vulnerability, identified under the code CVE-2018-6184, is a Directory Traversal vulnerability under the /_next request namespace. This means that an attacker can use specially crafted requests to navigate to arbitrary directories on the server and potentially access sensitive information.

When exploited, this vulnerability can lead to serious consequences for developers and companies using Next.js. For instance, attackers could obtain sensitive information such as usernames, passwords, or other confidential data. Additionally, the attacker could modify, delete, or corrupt data, leading to service downtime and data loss. In some cases, the attacker could even gain control over the entire server, allowing them to launch further attacks against other systems and services.

At s4e.io, users can easily and quickly learn about vulnerabilities in their digital assets using the platform's pro features. S4E provides comprehensive scans and analyses of websites and web applications, identifying potential vulnerabilities and providing actionable recommendations to mitigate them. With S4E, users can rest assured that their digital assets are protected against vulnerabilities such as CVE-2018-6184.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against the vulnerability. These include:

  • Updating to the latest version of Next.js: This is the simplest and most effective way to protect against the vulnerability. The latest version of Next.js includes a fix for CVE-2018-6184.
  • Disabling directory listing: This is a relatively easy precaution to implement. By disabling directory listing, attackers will not be able to browse the contents of directories, making it harder for them to exploit the vulnerability.
  • Implementing access controls: Access controls should be implemented to limit the paths that can be accessed under the /_next namespace. This will help prevent attackers from navigating to arbitrary directories.
  • Implementing input validation: Input validation should be performed on all user input to ensure that it does not contain any malicious content that could be used to exploit the vulnerability.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-6184 scanner - Local File Inclusion (LFI) vulnerability in Zeit Next.js | S4E