A critical vulnerability in Next.js's ImageResponse can enable server code execution through crafted SVG input. This flaw poses a significant security risk for web applications utilizing the Next.js framework. Developers are urged to update their systems promptly to mitigate potential exploitation.
Next.js ImageResponse Flaw Enables Server Code Execution via SVG
CyberSIXT Evidence Panel
Source marked as original reporting
Article by CyberSIXT