Tag: satori
1 article

Next.js Flaw Exposes Servers to Code Execution via ImageResponse
A vulnerability in Next.js's ImageResponse feature, powered by the Satori library, allows attackers to inject malicious code by passing tainted values into image generation, putting servers at risk of code execution. This flaw can be exploited when attacker-controlled values are inserted into SVG content, attributes, or styles during image creation.