zlacker

[parent] [thread] 0 comments
1. gonepi+(OP)[view] [source] 2025-12-03 16:28:11
Just to simplify this - our exploitation tests so far have shown that a standard Next.js application created via create-next-app and built for production is vulnerable to CVE-2025-66478 without any specific code modifications by the developer - so this is essentially exploitable out-of-the-box.
[go to top]