Permissive Cross-domain Security Policy with Untrusted...
Moderate severity
Unreviewed
Published
Jan 28, 2026
to the GitHub Advisory Database
•
Updated Jan 29, 2026
Description
Published by the National Vulnerability Database
Jan 28, 2026
Published to the GitHub Advisory Database
Jan 28, 2026
Last updated
Jan 29, 2026
Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.
References