CVE-2025-57822 | vercel next.js up to 14.2.31/15.4.6 next server-side request forgery (GHSA-4342-x723-ch2f)
A vulnerability described as critical has been identified in vercel next.js up to 14.2.31/15.4.6. The affected element is the function Next. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2025-57822. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.