A critical security vulnerability in Next.js can allow remote code execution when applications using the Node.js implementation of next/og ImageResponse embed attacker-controlled data in SVG content, attributes, or styles. The issue, tracked as GHSA-vcvr-r3jv-pc5j, affects Next.js versions 16.2.0 through 16.3.5 and has been fixed in version... Weiterlesen: Critical Next.js ImageResponse Flaw Enables Remote Code Execution via…
Intelligence View
⚡ tsecurity.de Intelligence
Critical Next.js ImageResponse Flaw Enables Remote Code Execution via Malicious SVG Input
A critical security vulnerability in Next.js can allow remote code execution when applications using the Node.js implementation of next/og ImageResponse embed…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege