Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
OopsSec Store - Walkthroughs Series' Articles
Back to Oopssec Store's Series
The ORM Didn't Save You: SQL Injection in a Prisma Codebase
Oopssec Store
Oopssec Store
Oopssec Store
Follow
Apr 28
The ORM Didn't Save You: SQL Injection in a Prisma Codebase
#
security
#
nextjs
#
webdev
#
tutorial
Comments
Add Comment
4 min read
Prompt Injection: 5 Ways to Bypass a Regex Blocklist on an LLM
Oopssec Store
Oopssec Store
Oopssec Store
Follow
Apr 30
Prompt Injection: 5 Ways to Bypass a Regex Blocklist on an LLM
#
security
#
webdev
#
ai
#
tutorial
Comments
Add Comment
5 min read
Client-Side Price Manipulation: Pay Whatever You Want at Checkout
Oopssec Store
Oopssec Store
Oopssec Store
Follow
May 3
Client-Side Price Manipulation: Pay Whatever You Want at Checkout
#
security
#
nextjs
#
webdev
#
tutorial
Comments
Add Comment
4 min read
How a fake npm package made Cursor backdoor a Next.js admin route
Oopssec Store
Oopssec Store
Oopssec Store
Follow
May 6
How a fake npm package made Cursor backdoor a Next.js admin route
#
security
#
nextjs
#
ai
#
webdev
Comments
Add Comment
8 min read
Why sameSite: "lax" doesn't save your Next.js admin routes from CSRF
Oopssec Store
Oopssec Store
Oopssec Store
Follow
May 11
Why sameSite: "lax" doesn't save your Next.js admin routes from CSRF
#
security
#
webdev
#
nextjs
#
tutorial
Comments
Add Comment
5 min read
Recovering a gift card code from its createdAt with a 10-line LCG
Oopssec Store
Oopssec Store
Oopssec Store
Follow
May 15
Recovering a gift card code from its createdAt with a 10-line LCG
#
security
#
webdev
#
nextjs
#
javascript
Comments
Add Comment
8 min read
path.join() Is Not Path Validation: A Next.js Traversal Walkthrough
Oopssec Store
Oopssec Store
Oopssec Store
Follow
May 16
path.join() Is Not Path Validation: A Next.js Traversal Walkthrough
#
security
#
nextjs
#
webdev
#
javascript
Comments
Add Comment
4 min read
The Env Variable Name Was Gone From the Bundle. The Value Wasn't.
Oopssec Store
Oopssec Store
Oopssec Store
Follow
May 20
The Env Variable Name Was Gone From the Bundle. The Value Wasn't.
#
security
#
nextjs
#
webdev
#
javascript
Comments
Add Comment
5 min read
Your Next.js API Route Is Leaking Diagnostics in Its 400 Responses
Oopssec Store
Oopssec Store
Oopssec Store
Follow
May 28
Your Next.js API Route Is Leaking Diagnostics in Its 400 Responses
#
security
#
nextjs
#
webdev
#
javascript
Comments
1
comment
5 min read
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account