-
Notifications
You must be signed in to change notification settings - Fork 5
Vulnerable JS Library (nextjs) #4803
Copy link
Copy link
Open
Labels
DAST[subject] Represents one or more findings from a DAST scan like Invicti or OWASP ZAP[subject] Represents one or more findings from a DAST scan like Invicti or OWASP ZAPcompliance[subject] Information and software security[subject] Information and software securityseverity:medium[subject] A SecurityHub severity of MEDIUM[subject] A SecurityHub severity of MEDIUM
Metadata
Metadata
Assignees
Labels
DAST[subject] Represents one or more findings from a DAST scan like Invicti or OWASP ZAP[subject] Represents one or more findings from a DAST scan like Invicti or OWASP ZAPcompliance[subject] Information and software security[subject] Information and software securityseverity:medium[subject] A SecurityHub severity of MEDIUM[subject] A SecurityHub severity of MEDIUM
From ZAP scan 2026-05-05
Severity: Medium
The identified library appears to be vulnerable.
Recommended Solution
Upgrade to the latest version of the affected library.
Other Info
The identified library nextjs, version 15.5.15 is vulnerable.
CVE-2025-59472
CVE-2026-27980
Evidence
https://anvilproject.org/_next/static/chunks/main-5fe8474ae46b6e58.js
https://explore.anvilproject.org/_next/static/chunks/main-48f8a7016b502370.js
https://data.humancellatlas.org/_next/static/chunks/main-5fe8474ae46b6e58.js
https://explore.data.humancellatlas.org/_next/static/chunks/main-48f8a7016b502370.js