Ssrf Exploitation

Server-Side Request Forgery (SSRF) detection, exploitation chains, and defense for Next.js, Vercel, and Node.js applications. Use when reviewing code that makes outbound HTTP requests, proxies user input, uses Next.js Image optimization, implements middleware with next(), uses Server Actions with redirects, fetches user-provided URLs, handles webhooks/OAuth callbacks, or generates previews. Covers CVE-2025-57822 (Next.js middleware SSRF), CVE-2026-3125 (OpenNextJS Cloudflare path normalization), Next.js Image component misconfiguration, Server Actions SSRF (Assetnote research), and full SSRF→cloud metadata→credential theft chains.

nickgallick 67931ce 9.1 KB Updated 0 repo stars

File contents

nickgallick/perlantir-fleet/tree/main/workspace-forge/skills/ssrf-exploitation commit 67931ce737

Frequently asked questions

npx skillmds add nickgallick/ssrf-exploitation