Web Hack List

Top 10 winner

Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library

Exploiting Web3's Hidden Attack Surface: Universal XSS on Netlify's Next.js Library

Netlify's ipx image-optimisation route builds its upstream fetch URL from the attacker-controlled X-Forwarded-Proto header, so a full URL ending in a question mark replaces the target entirely. Because the response is then cached under the requested path, this becomes stored cross-site scripting and full-response server-side request forgery on any Netlify Next.js site.

Record

Document
Exploiting Web3's Hidden Attack Surface: Universal XSS on Netlify's Next.js Library
Researcher
Sam Curry and @samwcyo
Published by
samcurry.net
Date
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Sam Curry and @samwcyo, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .