Skip to main content

Tag: satori

1 article

Developer workspace with laptop, notes, and coffee cups, with code editor on large monitor and blurred cityscape in…

Next.js Flaw Exposes Servers to Code Execution via ImageResponse

A vulnerability in Next.js's ImageResponse feature, powered by the Satori library, allows attackers to inject malicious code by passing tainted values into image generation, putting servers at risk of code execution. This flaw can be exploited when attacker-controlled values are inserted into SVG content, attributes, or styles during image creation.

Analyst 207