FixVibe

// discovery / spotlight

Vercel-Specific Exposure

_next/static, x-vercel-* headers, preview URLs — Vercel-isms that leak more than they should.

What it is

Every PaaS leaks shape. The shapes are stable enough across customers that Shodan, Wappalyzer, and FOFA index them — `cf-ray`, `x-vercel-id`, `x-amz-cf-id`, `x-nf-request-id` are reconnaissance starting points, not bug bounty findings. Vercel deployments are particularly identifiable because Next.js's distinctive `/_next/` path structure and `__NEXT_DATA__` script tag are practically a signed signature. Most of the time this is benign — the platform identity isn't a secret. The bugs sneak in when preview URLs leak, when source maps reference internal hostnames, or when feature-flagged unreleased pages ship to production routes.

How it happens

Vercel adds identifying headers such as `x-vercel-id` (deployment and region) and `x-vercel-cache` to responses, and Next.js apps carry recognisable asset paths. On Pages Router apps, the `__NEXT_DATA__` script in the HTML reveals build metadata, locale info, and sometimes server-side props that should have stayed server-side. Preview deployments at `*.vercel.app` get their own URL per branch — convenient for testing, dangerous when one of those URLs gets shared externally and hits search engines or wayback archives.

What an attacker gets

Recon impact dominates — knowing the host platform helps an attacker choose tactics (which WAF, which CDN behaviors to expect). Direct impact when preview URLs leak: preview deployments often have looser access controls than production (auth disabled, debug flags on, staging API endpoints), so a leaked preview URL bypasses your production hardening. Source map references in production bundles can leak the canonical preview hostname and infrastructure details.

// what fixvibe reports

What FixVibe reports

Runs on every URL scan: paste your app's URL, nothing to install. The free preview shows your top findings; Hobby and above unlock the full report. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Strip identifying headers if hiding Vercel as the host matters to you — Vercel's `headers` config can override or remove `x-vercel-*` headers. Don't link preview URLs from production code, marketing pages, or shared documents — once shared they get archived. Restrict preview deployments to authenticated team members via Vercel's password protection or SSO integration. Audit your Next.js config for `experimental` flags or debug routes that shouldn't ship to production. Use the same robots.txt rules for preview as for production (or stricter — preview deployments shouldn't be indexed at all). For Vercel-hosted side projects, the platform identification is fine to leave; for enterprise deployments, consider terminating at your own CDN to mask origin.

// run it on your own app

Continua a spedire mentre FixVibe vigila per te.

Paste your app's URL for a free preview. Nothing to install.

Discovery
133
test eseguiti in questa categoria
modules
16
controlli dedicati a discovery
every URL scan
230+
passive checks on each scan
Scan your URL free →

// latest checks · practical fixes · ship with confidence

Vercel-Specific Exposure: what it is and how to fix it · FixVibe