CVE-2026-94485 | Vercel Next.js up to 16.3.7 Development Server cross-site request forgery
A vulnerability was found in Vercel Next.js up to 16.3.7 and classified as problematic. The affected element is an unknown function of the component Development Server. Such manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2026-94485. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More