DEV Community

OopsSec Store - Walkthroughs Series' Articles

Back to Oopssec Store's Series
The ORM Didn't Save You: SQL Injection in a Prisma Codebase
Cover image for The ORM Didn't Save You: SQL Injection in a Prisma Codebase

The ORM Didn't Save You: SQL Injection in a Prisma Codebase

Comments
4 min read
Prompt Injection: 5 Ways to Bypass a Regex Blocklist on an LLM
Cover image for Prompt Injection: 5 Ways to Bypass a Regex Blocklist on an LLM

Prompt Injection: 5 Ways to Bypass a Regex Blocklist on an LLM

Comments
5 min read
Client-Side Price Manipulation: Pay Whatever You Want at Checkout
Cover image for Client-Side Price Manipulation: Pay Whatever You Want at Checkout

Client-Side Price Manipulation: Pay Whatever You Want at Checkout

Comments
4 min read
How a fake npm package made Cursor backdoor a Next.js admin route
Cover image for How a fake npm package made Cursor backdoor a Next.js admin route

How a fake npm package made Cursor backdoor a Next.js admin route

Comments
8 min read
Why sameSite: "lax" doesn't save your Next.js admin routes from CSRF
Cover image for Why sameSite: "lax" doesn't save your Next.js admin routes from CSRF

Why sameSite: "lax" doesn't save your Next.js admin routes from CSRF

Comments
5 min read
Recovering a gift card code from its createdAt with a 10-line LCG
Cover image for Recovering a gift card code from its createdAt with a 10-line LCG

Recovering a gift card code from its createdAt with a 10-line LCG

Comments
8 min read
path.join() Is Not Path Validation: A Next.js Traversal Walkthrough
Cover image for path.join() Is Not Path Validation: A Next.js Traversal Walkthrough

path.join() Is Not Path Validation: A Next.js Traversal Walkthrough

Comments
4 min read
The Env Variable Name Was Gone From the Bundle. The Value Wasn't.
Cover image for The Env Variable Name Was Gone From the Bundle. The Value Wasn't.

The Env Variable Name Was Gone From the Bundle. The Value Wasn't.

Comments
5 min read
Your Next.js API Route Is Leaking Diagnostics in Its 400 Responses
Cover image for Your Next.js API Route Is Leaking Diagnostics in Its 400 Responses

Your Next.js API Route Is Leaking Diagnostics in Its 400 Responses

Comments 1
5 min read