Friction

Switching reason · Permissions & security · Causes churn

Dropped Umami after a Next.js CVE led to a compromised server

1 source thread · first seen 2025-12

Summary

After a server was compromised through a disclosed Next.js vulnerability, the author stopped running Umami even though the issue was patched, because it is built on Next.js.

Affects
self-hoster

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“The CVE was disclosed, they patched it, but I’m not running Next.js-based analytics anymore”

Report this item