Credit Hacktron Vercel has released security patches for two criticalseverity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE202675604.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity