GHSA-2rmr-xw8m-22q9
MODERATECVE-2023-46729An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This could open door for other attack vectors:
- Affected
- >= 7.26.0, < 7.77.0
- Fixed in
- 7.77.0
- Published
- 2023-11-09
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference