Huge shout out to the random guy who walked up and asked if we needed a badge!! We are giving it to our friend who was stressed out about having to pay for it. Wish we’d asked for your name, but means a lot!!! @defcon
Two years ago, I reported an improper path parsing vulnerability in Next.js. Today, they reported the exact same vulnerability to their competitor, Vinext. Funny coincidence.
We've identified, responsibly disclosed, and confirmed 2 critical, 2 high, 2 medium, 1 low security vulnerabilities in Cloudflare's vibe-coded framework Vinext.
We believe the security of the internet is the highest priority, especially in the age of AI. Vibe coding is a useful