5

https://github.com/PwnFunction/...
Who led this flattening user input object into the Next.js codebase, also thinking that `runContext` is going to make better companion than `eval`?

Yet another reason to switch over Sapper and other Svelte minimalistic solutions, in my opinion.

Comments
  • 1
    Before someone toggles on smartass switch, there is a related CVE: https://github.com/advisories/...

    Yes, this vulnerability trickster app supposedly has `amp` config value activated, but it's the feature of Next.js, and backdoor is becoming clear. It may be obvious to you, me, but not the users that believe it to be safe. Either update framework or disable `amp` option, for all I care.
Add Comment