I'd like to announce a new vulnerability chain we found that starts with an SVG parser bug. It affects multiple products and can lead to RCE.
I created https://t.co/3Tk4B6amtx to share more about the chain, which I'm calling "VectorFreed" for now.
I started looking into this early this month and have since confirmed command execution in several products that process SVGs. The root issue is CVE-2026-96889, with fixes in librsvg 2.63.2 and the 2.62.4 backport.
The repo has an early overview and references for now. I'll share the technical write-up in the coming weeks.
I'd like to announce a new vulnerability chain we found that starts with an SVG parser bug. It affects multiple products and can lead to RCE.
I created https://t.co/3Tk4B6amtx to share more about the chain, which I'm calling "VectorFreed" for now.
I started looking into this early this month and have since confirmed command execution in several products that process SVGs. The root issue is CVE-2026-96889, with fixes in librsvg 2.63.2 and the 2.62.4 backport.
The repo has an early overview and references for now. I'll share the technical write-up in the coming weeks.
We recently found a new RCE chain affecting the Node.js ImageResponse implementation in Next.js.
Vercel has published CVE-2026-94545. Next.js versions from 16.2.0 through 16.3.5 are affected. Upgrade to Next.js 16.3.6.
I'll share more details soon, once the remaining upstream advisories are out!
Credit also to @ragrocks77, who discovered this together with me
Post: https://t.co/zX7dJ6WIoj
when the AI provider does something similar: Look what did we do🤤🤤🤤🤤🤤
when some elite guys do it: 🤬🤬🤬🤬 youre being unprofessional stop 🤬🤬🤬🤬 youre violating my ego😭😭😭😭😭
We are not stopping at OpenAI.
Today we’re publishing HEIF Heist, a months-long investigation by our security research team into vulnerabilities in libheif.
The research uncovered attack paths affecting OpenAI, Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and others.
https://t.co/QXWulEXjJp