Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass
Description
Published by the National Vulnerability Database
Oct 2, 2026
Published to the GitHub Advisory Database
Oct 7, 2026
Reviewed
Oct 7, 2026
Last updated
Oct 7, 2026
In Next.js App Router applications built with webpack, metadata image routes such as opengraph-image and twitter-image ignore the
dynamicParamsroute segment option. An attacker can request metadata image URLs for dynamic segments that were deliberately excluded fromgenerateStaticParams().References