Critical Thinking - Bug Bounty Podcast cover image

Episode 168: XSSDoctor - Client-side Path Traversal Research

Critical Thinking - Bug Bounty Podcast

00:00

Next.js secondary context path traversal

They explain how Next's await params on the server can decode encodings, causing server-side traversal with victim creds.

Play episode from 52:59
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app