Skip to main content

Share story

Security Infrastructure

Next.js patches critical server code execution flaw in image generation

Next.js patches critical server code execution flaw in image generation Image: Primary
Vercel fixed a critical Next.js flaw on September 22 that could let attackers run code on a server through ImageResponse, the feature used to generate social preview images. The risk applies when an application places attacker-controlled values into SVG content, attributes or styles while ImageResponse runs on Node.js. The flaw affects Next.js 16.2.0 through 16.3.5; version 16.3.6 contains the fix. Next.js 15 and the Edge version of ImageResponse are unaffected. The Hacker News found no public reports of attacks or exploit code as of September 23, and its check found that npm audit did not flag affected version 16.3.5.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Infrastructure
Security Infrastructure

F5 patches exploited BIG-IP APM flaw as U.S. agencies face Friday deadline

F5 has released security updates for a critical BIG-IP APM flaw that it says attackers have exploited to run code remotely. BIG-IP APM manages access to organizational networks and applications. The vulnerability affects configura...

Infrastructure AI
Infrastructure AI

German and Dutch agencies launch €40 million AI chip design challenge

Germany's SPRIND and the Netherlands' NADI have launched a joint €40 million challenge to fund European AI chip design. The agencies plan to select seven teams for an initial stage, awarding each €2.6 million, then advance three t...

Capital AI
Capital AI

German tax software startup mika raises €6 million

Berlin-based mika has raised €6 million in seed funding to expand its accounting and tax platform for small German limited companies. Smedvig Ventures led the round, with participation from Wecken & Cie., individual investors and ...

Security
Security

Ryuk ransomware participant receives 24-month prison sentence

An Armenian man who helped gain access to U.S. corporate networks for Ryuk ransomware attacks has been sentenced to 24 months in prison and three years of supervised release. Karen Serobovich Vardanyan pleaded guilty in July after...

Capital Products
Capital Products

Wrtn selects lead underwriter for planned South Korean IPO

Wrtn Technologies has selected Mirae Asset Securities as lead underwriter to arrange a planned initial public offering in South Korea. The appointment gives the AI startup a bank to organize its prospective listing. The offering r...

Science Capital
Science Capital

Andreessen Horowitz founders back $42 million alternative to college

A two-year private school backed by Andreessen Horowitz founders Marc Andreessen and Ben Horowitz has raised $42 million for an alternative to college. The Horowitz Andreessen Academy plans to teach through independent, business-o...