GitHub's Advisory Database published a security advisory on 7 October 2026 about Next.js. It concerns the development server, which starts when a developer runs the next dev command. The advisory says that server offers a Model Context Protocol endpoint, a way for tools to ask for project data. The endpoint never checks which website sent a request. A malicious site that a developer visits could therefore pull out the project's folder path, code fragments from error reports, the route list, and development logs.
The advisory says only apps started with next dev are affected, and live deployments do not offer the endpoint. Its text gives no severity rating, no list of affected versions, and no fix steps. It links to CVE-2026-94486 and the Next.js v16.3.8 release page, but does not say that release fixes the flaw. It also does not say whether anyone has used the flaw.
This is our reading, not the advisory's. An origin check asks where a request came from. Without one, a web page open in the developer's browser can send requests to a service on the same machine. Leaders may want to ask which Next.js versions their developers run, and whether dev machines hold other credentials.