CVE-2026-94486
MediumAdvisory
Published 7 Oct 2026In the index since 8 Oct 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.4
- base score, highest
- EPSS
- 0.001
- 1st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 54
- of 18,053 indexed, latest versions
- Container images
- 51
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Next.js has information disclosure in development server's Model Context Protocol endpoint
Carried by container images the latest versions of 54 of 18,053 indexed charts deploy, on 51 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nextnpm | 16.0.3, 16.0.10, 16.1.3, 16.1.6+13 more | 16.3.8 | 51 |
- OSV records
- GHSA-39w2-rjm5-chcv
Charts affected
54 by stars
Container images carrying it
51 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.