Dispatch
An AI agent found the libheif RCE behind Next.js image optimization, and Vercel published the full disclosure timeline
Vercel's 18 September post walks through a remote code execution bug in libheif's AVIF decoder that Hacktron's AI security platform first surfaced as a Next.js image optimization flaw in August, then traced upstream. The timeline: Hacktron reported with a working proof of concept on 11-12 August, Vercel deployed a platform-wide mitigation on 13 August, the Next.js team reached the libvips maintainer on 19 August, and libheif 1.23.2 shipped the fix on 25 August alongside a Next.js security release that disabled AVIF outright. The advisory is GHSA-g89c-p67h-r497, and the blast radius covers ImageMagick, WordPress and sharp as well.
Source
↳ Follow the thread