SECURITY·중요도 9·2026. 09. 23.·The Hacker News

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

── KO ──────────────────

Next.js의 이미지 응답 기능에서 취약점이 발견되어 서버 코드 실행 위험이 존재합니다.

Next.js의 새로운 보안 취약점이 발견되어 공격자가 조작된 SVG 입력을 통해 서버에서 코드를 실행할 수 있는 위험이 존재합니다. 이 취약점은 공격자가 요청 URL에서 읽은 텍스트와 같은 제어 가능한 값을 이미지에 삽입할 때 악용될 수 있습니다. Vercel은 이 결함을 9월 22일에 수정한 것으로 보고했습니다.


── EN ──────────────────

A security vulnerability in Next.js allows server code execution via crafted SVG input.

A new security vulnerability has been discovered in Next.js that might allow attackers to execute code on a server through the ImageResponse feature. This risk arises when an application incorporates values controlled by an attacker, such as text from the request URL, into the generated image. Vercel, the developer of Next.js, reported that this flaw was fixed on September 22.

원문 보기 →목록으로