A vulnerability has been reported in Next.js which could allow an attacker to proxy requests to arbitrary destinations leading to exposure of internal services or cloud metadata endpoints.
Target Audience:
All end-user individuals and organizations using Next.js.
Risk Assessment:
High risk of unauthorized access to sensitive information.
Impact Assessment:
Potential exposure of internal services or cloud metadata endpoints.
The information provided herein is on "as is" basis, without warranty of any kind.