严重的Next.js ImageResponse缺陷可通过精心设计的SVG输入导致服务器代码执行
Vercel表示, Next.js中的一个新安全漏洞可能允许攻击者通过ImageResponse在服务器上运行代码,该功能可生成Open Graph和其他社交预览图像。
原文标题:Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
信源:The Hacker News | 阅读原文
A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as
—— 开源情报自动采集 · 综合