Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. next
  4. ›
  5. CVE-2025-55173

CVE-2025-55173: Next.js Content Injection Vulnerability for Image Optimization

August 29, 2025

A vulnerability in Next.js Image Optimization has been fixed in v15.4.5 and v14.2.31. The issue allowed attacker-controlled external image sources to trigger file downloads with arbitrary content and filenames under specific configurations. This behavior could be abused for phishing or malicious file delivery.

All users relying on images.domains or images.remotePatterns are encouraged to upgrade and verify that external image sources are strictly validated.

More details at Vercel Changelog

References

  • github.com/advisories/GHSA-xv57-4mr9-wg8v
  • github.com/vercel/next.js
  • github.com/vercel/next.js/commit/6b12c60c61ee80cb0443ccd20de82ca9b4422ddd
  • github.com/vercel/next.js/security/advisories/GHSA-xv57-4mr9-wg8v
  • nvd.nist.gov/vuln/detail/CVE-2025-55173

Code Behaviors & Features

Detect and mitigate CVE-2025-55173 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 14.2.31, all versions starting from 15.0.0 before 15.4.5

Fixed versions

  • 14.2.31
  • 15.4.5

Solution

Upgrade to versions 14.2.31, 15.4.5 or above.

Impact 4.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-20: Improper Input Validation

Source file

npm/next/CVE-2025-55173.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 30 Aug 2025 00:19:44 +0000.