A critical severity vulnerability has been discovered in the Next.js open-source web development framework, potentially allowing attackers to bypass authorization checks. The flaw, tracked as CVE-2025 ...
Pantheon built its reputation on WordPress and Drupal. Now it wants a seat at the table for what comes next — and it's betting that table is being set by Next.js. The San Francisco-based managed ...
A coordinated campaign targeting software developers with job-themed lures is using malicious repositories posing as legitimate Next.js projects and technical assessment materials, including ...