Security Audit for Next.js Apps
Next.js is the default stack for many AI coding tools, including v0, Cursor, and Claude Code. Its blend of server and client code makes it easy to ship fast and easy to misplace a security boundary. We review where your checks actually run.
30-minute intro call · fixed-scope quote · human review, not scanner output. Read client case studies.
What we find most often in Next.js apps
These issues come from how the App Router blends server and client code, and from framework versions that fall behind on security releases.
Middleware as the only auth layer
CVE-2025-29927 showed that middleware could be bypassed with a crafted header in affected versions before 15.2.3 and 14.2.25. Middleware is a convenience layer; data access needs its own checks.
Server actions treated as private
Server actions compile to public POST endpoints. Any action that changes data must check the session, ownership, and input inside the action itself.
Route handlers without authorization
API routes generated for dashboards often verify login but not ownership, or read the user ID from the request instead of the session.
NEXT_PUBLIC_ secrets
Variables prefixed `NEXT_PUBLIC_` are inlined into client bundles at build time. A secret key with that prefix is public, even after you rename it, until it is rotated.
Self-hosting and image configuration
Self-hosted deployments and permissive `images.remotePatterns` or rewrite configuration can open server-side request forgery paths to internal services.
Unpatched framework versions
Next.js publishes security releases regularly. Apps pinned to an old minor version miss fixes for issues in middleware, caching, and server components.
What a Next.js security audit covers
A fixed-scope review of your Next.js repository and deployment configuration, delivered as a prioritized report.
Checks you can run yourself
Start here before you book anything. If any of these fail or you are not sure how to check, that is the signal to get a second pair of eyes.
- Check your `next` version in package.json and upgrade to the latest patch release of your major version.
- Search for `"use server"` and confirm every exported action checks the session before changing data.
- Confirm protected API routes check auth themselves rather than relying only on middleware.
- List every `NEXT_PUBLIC_` variable and confirm none is a secret.
- Review `images.remotePatterns` and rewrites in next.config and remove broad wildcards.
Want a scored version? Take the free vibe code security check or work through the 25-point launch checklist.