@rauchg tried a few approaches but it still flags it, must be checking for the actual code fixes? even renamed the vendored files and the versions inside the sources
@rauchg I'm trying to submit a hackerone report for the WAF, before doing so I need to test it on Vercel. It doesn't let me create a vuln app. Would appreciate it if we could talk :) thanks
@_sy1vi3 wonder if we could have a chat. Found something interesting that also gives the same RCE.
It's a little different, but works on the same premise.
Would appreciate it, meanwhile I've contacted Meta, but they are slow. thanks :)