Node.js ImageResponse Implementation Vulnerability Enables Remote Code Execution

A critical vulnerability in Next.js could allow remote code execution in applications that use the Node.js implementation of ImageResponse from the next/og package. The issue, tracked as GHSA-vcvr-r3jv-pc5j, affects Next.js versions 16.2.0 through 16.3.5 and has been fixed in version 16.3.6. The flaw exists when an application passes attacker-controlled input into SVG content, SVG attributes, […]

This article has been indexed from Cyber Security News

Read the original article: