High severity7.5NVD Advisory· Published Jan 24, 2018· Updated Jun 17, 2026
CVE-2018-6184
CVE-2018-6184
Description
ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nextnpm | >= 1.0.0, < 4.2.3 | 4.2.3 |
Affected products
18cpe:2.3:a:zeit:next.js:4.0.0:*:*:*:*:*:*:*+ 16 more
- cpe:2.3:a:zeit:next.js:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.1.4:canary_1:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.1.4:canary_2:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.2.0:canary_1:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:zeit:next.js:4.2.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-m34x-wgrh-g897ghsaADVISORY
- github.com/zeit/next.js/releases/tag/4.2.3nvdIssue TrackingThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2018-6184ghsaADVISORY
- github.com/vercel/next.js/releases/tag/4.2.3ghsaWEB
News mentions
0No linked articles in our index yet.