Vercel patches two critical unauthenticated RCE bugs in the Next.js framework.
A CVSS 9.5 Rails Active Storage flaw lets unauthenticated attackers read arbitrary server files through crafted image uploads.