CyberSecurity News
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
AI summary
A security vulnerability has been discovered in Next.js that could enable attackers to execute code on a server. The issue is related to the ImageResponse feature, which generates social preview images, and occurs when an application incorporates user-controlled values into the image. This can include text from the request URL. The vulnerability was addressed by Vercel, the developer of Next.js, in a fix implemented on September 22. The fix was included in a new version of Next.js, mitigating the risk of server code execution via crafted SVG input.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

