Skip to content

Vulnerable JS Library (nextjs) #4803

@dsotirho-ucsc

Description

@dsotirho-ucsc

From ZAP scan 2026-05-05
Severity: Medium

The identified library appears to be vulnerable.

Recommended Solution

Upgrade to the latest version of the affected library.

Other Info

The identified library nextjs, version 15.5.15 is vulnerable.

CVE-2025-59472
CVE-2026-27980

Evidence

https://anvilproject.org/_next/static/chunks/main-5fe8474ae46b6e58.js
https://explore.anvilproject.org/_next/static/chunks/main-48f8a7016b502370.js
https://data.humancellatlas.org/_next/static/chunks/main-5fe8474ae46b6e58.js
https://explore.data.humancellatlas.org/_next/static/chunks/main-48f8a7016b502370.js

="15.5.15",X=(0,P.default)(),W=e=>[].slice.call(e),G=!1;class q extends E.default.
Component{componentDidCatch(e,t){this.props.fn(e,t)}componentDidMount

Metadata

Metadata

Assignees

Labels

DAST[subject] Represents one or more findings from a DAST scan like Invicti or OWASP ZAPcompliance[subject] Information and software securityseverity:medium[subject] A SecurityHub severity of MEDIUM

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions