
In a small Next.js 15.5.2 App Router blog app (TypeScript, 17 source files, 352 lines), all 12 attack tests (A01–A12) succeeded before fixes and were all blocked after them.
Summaries like this, in your inbox every morning.
The write-up's test app is deliberately small: Next.js 15.5.2 on the App Router, React 19.1, TypeScript, SQLite via node:sqlite, and Node.js 22.22.0, with 17 source files amounting to 352 lines. Before fixes, all 12 attack tests succeeded; after fixes, all 12 were blocked. The tests ran only against a local copy and dummy data, and the author warns against trying them on a live server.
Several holes trace back to specific shortcuts. A profile-update form sent the target's userId in a hidden field, so changing it and adding role=admin let a logged-in Bob rename Alice and promote her; the fix reads the target from the session and accepts only the name. Route handlers had no auth or ownership check at all, so deleting other people's posts and reading drafts without logging in both worked, and a users API returned SELECT * output including plaintext passwords. The password fix uses scrypt with a salt and the settings N=2^15, r=8, p=3, which OWASP lists alongside the N=2^17, r=8, p=1 minimum as using about 32MiB per computation.
Other flaws were about what was never restricted: a search box and an ID parameter let SQL be embedded into queries; an image proxy fetched any URL handed to it (SSRF), a concern the author ties to private networks like Railway's *.railway.internal; uploads used the client-supplied file name, so ../../pwned.html was written outside public/uploads; CORS echoed the request Origin with credentials allowed; the post-login redirect followed an absolute URL to an external site; and the session cookie lacked HttpOnly, Secure, and SameSite with a one-year lifetime and a token made from Math.random(). The version pin also mattered — the author notes AI often writes the version it learned and misses later patches. After twelve app-specific Semgrep rules were written, 17 matches appeared before the fixes and 0 after, but the author cautions that this and the zero public-rule findings only mean no rule matched, not that the code is safe.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Mikita Balesni, Jasmine Wang, and Tomek Korbak said on October 8 they were fired the previous week and that no…

Nathan Lambert published an essay arguing AI progress will accelerate through engineering and infrastructure g…

ALPHA FORGE's new sandbox.py calls the same inference orchestrator as the daily batch but never calls the ledg…

Writing on Zenn, Taichi Endoh — a clinical engineer and AI engineer — says the first step in a leak is to defi…

The guide walks through creating a TypeScript MCP server with @modelcontextprotocol/sdk, registering a single…

A Zenn field report on Claude Code 2.1.286〜2.1.288 (October 2026, Windows) lists five failures when a Mod buil…
