Collected research
Digging for SSRF in NextJS apps
Examines Next.js server actions and redirect handling to turn attacker-controlled Host headers and application redirects into server-side requests. The technique can make a vulnerable deployment fetch internal or external resources and return response data.
Record
- Researcher
- Shubham Shah
- Published by
- slcyber.io
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Shubham Shah, first published at the original source. Preserved copies are kept so the citation survives its host.