Nextjs Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Credit Hacktron Vercel has released security patches for two criticalseverity vulnerabilities in the Nextjs web framework both of which allow unauthenticated remote code execution one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem The Windows path traversal tracked as CVE202675604