Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library
Overview On August 24th, 2022, we reported a vulnerability to Netlify affecting their Next.js “netlify-ipx” repository which would allow an attacker to achieve persistent cross-site…