Next.js App Router & React Server Component Security

Next.js Security Scanner & Vulnerability Audit

Scan your Next.js application for Server Action leaks, SSR data exposure, and middleware auth bypasses. Get real-world vulnerability detection with ready-to-merge Cursor and Claude Code fix prompts.

4 Critical Next.js Vulnerabilities We Check

Next.js combines frontend and backend in one repository. When boundaries blur, subtle security mistakes expose your entire database.

Unauthenticated Server Actions

Server Actions are public POST endpoints reachable via direct HTTP requests. Declaring `use server` does not add authentication. If your mutation fails to check `auth()`, any visitor can trigger mutations by guessing the action hash.

Risk: Unauthorized data mutation • Privilege escalation

SSR Data Leakage in RSC Payloads

When a React Server Component fetches user data from Prisma or Drizzle, all returned object properties (including password hashes or Stripe customer IDs) get serialized into the HTML payload even if your JSX only renders the username.

Risk: PII exposure • Internal API token leakage

Middleware Matcher Route Bypasses

Relying solely on `middleware.ts` for route protection is dangerous when matcher patterns miss sub-routes or static files. If an attacker appends query parameters or visits an unlisted API route, middleware execution can be bypassed entirely.

Risk: Route protection bypass • Broken access control

Missing Strict Content Security Policy

Next.js App Router relies heavily on inline script hydration. Without a proper nonce-based CSP configuration, standard cross-site scripting vulnerabilities in third-party packages or client inputs can hijack customer sessions.

Risk: Session hijacking • XSS script injection
Engineering Deep Dive

How to Fix a Vulnerable Server Action

Below is a real-world Server Action pattern detected by our scanner, followed by the exact patch generated by our AI remediation engine.

Vulnerable: Unauthenticated Mutation
"use server";

export async function deleteOrganization(orgId: string) {
  // Vulnerability: Anyone can call this
  // with any orgId without an active session!
  await db.organization.delete({
    where: { id: orgId },
  });
  return { success: true };
}
Hardened: Session & Role Verification
"use server";
import { auth } from "@/lib/auth";

export async function deleteOrganization(orgId: string) {
  const session = await auth();
  if (!session?.user?.id) {
    throw new Error("Unauthorized");
  }
  // Enforce tenant boundary
  await db.organization.delete({
    where: { id: orgId, ownerId: session.user.id },
  });
  return { success: true };
}

The Next.js Pre-Launch Security Checklist

Strict Content Security Policy (CSP): Configure CSP nonces in `middleware.ts` or set strict HTTP response headers in `next.config.mjs`.
Environment Variable Isolation: Ensure private tokens never carry the `NEXT_PUBLIC_` prefix to prevent browser bundle leakage.
Image Optimizer Domain Whitelist: Restrict `remotePatterns` in `next.config.mjs` to trusted CDNs to block SSRF proxying attacks.
HSTS & Secure Cookie Directives: Set `Strict-Transport-Security: max-age=31536000; includeSubDomains` and `SameSite=Lax` on all session cookies.

Test your Next.js app in 3 to 5 minutes

Verify your domain and run our multi-engine scanner against your live routes to discover leaks before going to production.