Three bugs in vinext's alpha, Cloudflare's AI-built Next.js replacement
Three bugs in vinext's alpha, the Next.js replacement Cloudflare built with AI for about $1,100: a middleware auth bypass, a header-sanitization bypass, and a reflected XSS.
Security research and bug bounty, done the boring way: reported to the vendor, fixed, then written up here.
Three bugs in vinext's alpha, the Next.js replacement Cloudflare built with AI for about $1,100: a middleware auth bypass, a header-sanitization bypass, and a reflected XSS.
A white-box audit of the end-to-end encrypted booking platform OpenReception found 16 vulnerabilities, four of them critical.
How missing authorization checks in Zammad's REST API let agents execute group-restricted AI text tools and inject unauthorized ticket context into AI prompts.
Authentication bypass via i18n locale prefix; middleware matcher evaluates unsanitized pathname
Middleware header sanitization bypass; missing x-middleware-override-headers allows header spoofing
Reflected XSS via unescaped attribute names in next/head SSR serializer
one tenant’s throttle row disables the PIN brute-force throttle for the same identifier in other tenants
invite confirmation token is replayable within its validity window and re-issues a registration-bootstrap cookie