4 ms·
Just to simplify this - our exploitation tests so far have shown that a standard Next.js application created via create-next-app and built for production is vul
by gonepivoting 10mo ago
Just to simplify this - our exploitation tests so far have shown that a standard Next.js application created via create-next-app and built for production is vulnerable to CVE-2025-66478 without any specific code modifications by the developer - so this is essentially exploitable out-of-the-box.