Information disclosure
Description
Proof of Concept
Commit Details
Author: JJ Kasper
Date: 2026-03-18 21:36 UTC
Message:
Triage Assessment
Vulnerability Type: Information disclosure
Confidence: MEDIUM
Reasoning:
The change normalizes encoded dynamic placeholders in app routes to ensure encoded segments are correctly treated as dynamic parameters rather than literal path segments. This prevents potential leakage or misinterpretation of route parameters (e.g., root param placeholders) during prefetching and route parsing, which could expose parameter names or allow edge-case bypasses. Tests explicitly guard against encoded placeholders being exposed in prefetch responses.
Verification Assessment
Vulnerability Type: Information disclosure
Confidence: MEDIUM
Affected Versions: 16.2.2 and earlier (16.2 release line); fixed in a subsequent release after this commit