Next.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content

A critical vulnerability in Next.js could let unauthenticated remote attackers execute code on affected servers by supplying crafted input that gets rendered into SVG content during dynamic image generation. This issue, tracked as GHSA-vcvr-r3jv-pc5j, affects the Node.js implementation of ImageResponse in the next/og package. The flaw impacts Next.js versions 16.2.0 to 16.3.5. Vercel has released […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: