Next.js 16.3.8 dev-server MCP disclosure and where the Sume key lives

Next.js 16.3.8 fixes a low-severity dev-server MCP disclosure and a high-severity image SSRF. How to keep a Sume API key server-side as you upgrade.

4 min readSume
All posts

Upgrade to Next.js 16.3.8, and treat the dev-server MCP fix as a reminder to keep a Sume API key out of anything a tool, an agent or the browser can read. The Next.js releases page lists fixes for an SSRF in Image Optimization rated high, cache poisoning in SSG and ISR, Draft Mode leaks, and an information disclosure in the dev-server MCP rated low.

This post is not a security advisory. It is a short list of key-handling habits for apps that call Sume, framed by what that release fixes.

What the release page lists

Severities are as listed on the page.

vercel/next.js releases, v16.3.8 (read 2026-10-03)
AreaSeverity listed
Image Optimization SSRFHigh
Cache poisoning in SSG and ISRListed
Draft Mode leaksListed
Dev-server MCP information disclosureLow

What Sume says about keys

A Sume API key spends your credits and has no browser-safe variant. Sume's docs say never to ship one to client JavaScript, a mobile bundle or a NEXT_PUBLIC_* variable, and to put your own endpoint in front of Sume. The server-side proxy pattern in the authentication docs attaches the key on the server and passes the response through.

That guidance matters more when a development server, an editor agent and a language model all run next to your environment file.

Habits that survive any release

None of these depends on a particular Next.js version.

  • Name the variable SUME_API_KEY with no NEXT_PUBLIC_ prefix, and read it only inside Route Handlers and server code.
  • Keep the key out of files that an editor agent is likely to read or paste. Use your host's secret store for deployed environments.
  • Rotate any key that appears in logs or chat history. Sume's guidance says this explicitly.
  • Send exactly one credential header. A request with both Authorization: Bearer and x-api-key fails with 401 unauthorized.

Serving generated images

Sume results carry Sume media URLs, for example under media.sume.com; raw provider URLs are not public API outputs. If you render them with the Next.js image component, the image fix in this release is relevant to your configuration. Allow only the hosts you serve from, and review what your remote patterns accept after upgrading.

// next.config.ts: allow only the Sume media host
import type { NextConfig } from "next";

const config: NextConfig = {
  images: {
    remotePatterns: [
      { protocol: "https", hostname: "media.sume.com" },
    ],
  },
};

export default config;

The webhook route

If the same app receives Sume webhooks, read the raw body in the Route Handler before parsing, verify the sume-v1 signature against SUME_COM_WEBHOOK_SIGNING_SECRET, and store the event keyed by job_id before returning 2xx. Sume retries up to 10 times, so a handler that is slow or throws turns one event into several.

The webhook secret is as sensitive as the API key for your purposes: with it, someone could forge events. Keep it on the same footing.

After you upgrade

Confirm the new version is what is deployed, not only what is in your lockfile, and run one read-only call such as GET /v1/me through your proxy to check the key path still works. Then retest the image route with a real Sume media URL.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume