Security Team Discloses Critical Next.js RCE Bug, Complains About LLM API Access Denials

joshua_saxe · x · 2026-08-28

Security researcher S1r1u5 expressed frustration that their team is denied "trusted access" to OpenAI, Anthropic, and Google's cybersecurity tools due to lack of notoriety, vowing to keep releasing high-quality research to earn it. Separately, HacktronAI revealed a critical Remote Code Execution (RCE) vulnerability in Next.js, urging immediate updates for self-hosted instances while noting Vercel-hosted environments are safe. Technical details and a PoC will be published soon.

Original post →

More from Safety

Safety channel →