Medium severity6.1NVD Advisory· Published Jan 28, 2026· Updated Jun 17, 2026
CVE-2025-13984
CVE-2025-13984
Description
Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2025-122nvdVendor Advisory
News mentions
0No linked articles in our index yet.