Umami is vulnerable - upgrade immediately

https://jlai.lu/post/29883346

Link? Did you discover this yourself? There is no actual info here.
RCE Confirmed via Umami Dependency (Next.js CVE-2025-66478) · Issue #3852 · umami-software/umami

Describe the Bug I am reporting this to confirm that a critical vulnerability in Next.js (CVE-2025-66478) led to a root-level compromise on my server, where Umami was running. I understand Umami ha...

GitHub
Thank you!