Vercel vulnerabilities
2 CVEs tracked
In our reporting, Vercel is primarily noted for its platform components (Next.js, Astro adapter) and its abuse in phishing campaigns. Key themes include an image optimization flaw in self-hosted Next.js (CVE-2026-64644), an unauthenticated access vulnerability in the Astro Vercel adapter (CVE-2026-73424), and agent infrastructure flaws allowing tool triggers without model authorization. Defenders should focus on exploitation of CVE-2026-73424 via the `x-vercel-isr` header and the platform's increasing use as a phishing hosting source.
Azərbaycanca: Hesabatlarımızda Vercel əsasən platforma komponentləri (Next.js, Astro adapteri) və onun fişinq kampaniyalarında sui-istifadəsi ilə bağlı qeyd olunur. Kritik mövzulara öz-özünə host edilən Next.js-də şəkil optimallaşdırması boşluğu (CVE-2026-64644), Astro Vercel adapterində autentifikasiyasız giriş zəifliyi (CVE-2026-73424) və AI agent infrastrukturunda alət çağırışlarının model icazəsi olmadan trigger edilməsi daxildir. Müdafiəçilər xüsusilə `x-vercel-isr` header-inə əsaslanan CVE-2026-73424 istismarına, həmçinin platformanın fişinq hosting mənbəyi kimi artan istifadəsinə diqqət yetirməlidir.
This vendor's CVEs2
This hub is built from skopnix's own reporting on Vercel: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.