Next.js Security Scanner & Vulnerability Audit
Scan your Next.js application for Server Action leaks, SSR data exposure, and middleware auth bypasses. Get real-world vulnerability detection with ready-to-merge Cursor and Claude Code fix prompts.
4 Critical Next.js Vulnerabilities We Check
Next.js combines frontend and backend in one repository. When boundaries blur, subtle security mistakes expose your entire database.
Unauthenticated Server Actions
Server Actions are public POST endpoints reachable via direct HTTP requests. Declaring `use server` does not add authentication. If your mutation fails to check `auth()`, any visitor can trigger mutations by guessing the action hash.
SSR Data Leakage in RSC Payloads
When a React Server Component fetches user data from Prisma or Drizzle, all returned object properties (including password hashes or Stripe customer IDs) get serialized into the HTML payload even if your JSX only renders the username.
Middleware Matcher Route Bypasses
Relying solely on `middleware.ts` for route protection is dangerous when matcher patterns miss sub-routes or static files. If an attacker appends query parameters or visits an unlisted API route, middleware execution can be bypassed entirely.
Missing Strict Content Security Policy
Next.js App Router relies heavily on inline script hydration. Without a proper nonce-based CSP configuration, standard cross-site scripting vulnerabilities in third-party packages or client inputs can hijack customer sessions.
How to Fix a Vulnerable Server Action
Below is a real-world Server Action pattern detected by our scanner, followed by the exact patch generated by our AI remediation engine.
"use server";
export async function deleteOrganization(orgId: string) {
// Vulnerability: Anyone can call this
// with any orgId without an active session!
await db.organization.delete({
where: { id: orgId },
});
return { success: true };
}"use server";
import { auth } from "@/lib/auth";
export async function deleteOrganization(orgId: string) {
const session = await auth();
if (!session?.user?.id) {
throw new Error("Unauthorized");
}
// Enforce tenant boundary
await db.organization.delete({
where: { id: orgId, ownerId: session.user.id },
});
return { success: true };
}The Next.js Pre-Launch Security Checklist
Test your Next.js app in 3 to 5 minutes
Verify your domain and run our multi-engine scanner against your live routes to discover leaks before going to production.
