Top 10 winner
Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library
Exploiting Web3's Hidden Attack Surface: Universal XSS on Netlify's Next.js Library
Netlify's ipx image-optimisation route builds its upstream fetch URL from the attacker-controlled X-Forwarded-Proto header, so a full URL ending in a question mark replaces the target entirely. Because the response is then cached under the requested path, this becomes stored cross-site scripting and full-response server-side request forgery on any Netlify Next.js site.
Record
- Document
- Exploiting Web3's Hidden Attack Surface: Universal XSS on Netlify's Next.js Library
- Researcher
- Sam Curry and @samwcyo
- Published by
- samcurry.net
- Date
- Topic
- XSS
In the archive
Related sources
- Vendor advisory Advisory
Tags
This page is the archive's own catalogue record. The research is the work of Sam Curry and @samwcyo, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .