Back

MEDIUM

Next.js: Cross-site scripting in beforeInteractive scripts with untrusted input

Published May 13, 2026

Description

Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vulnerability is fixed in 15.5.16 and 16.2.5.

Affected products

Remediation

Red Hat statement

This is a Moderate cross-site scripting (XSS) vulnerability affecting Next.js applications. The flaw occurs when applications employ `beforeInteractive` scripts with unsanitized, untrusted content, enabling remote attackers to execute arbitrary JavaScript. The requirement for this specific script strategy and attacker-controlled input limits the overall exposure in Red Hat deployments.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 13, 2026
Updated May 13, 2026
Reserved May 6, 2026
CISA Vulnrichment
Updated May 13, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 13, 2026
ENISA EUVD
Assigner GitHub_M
Published May 13, 2026
Updated May 13, 2026
Exploited since n/a
EUVD-2026-30082 GHSA-GX5P-JG67-6X7H