Skip to content

fix(deps): bump next to 16.3.6 (critical RCE, GHSA-vcvr-r3jv-pc5j) - #5

Open
pollosp wants to merge 1 commit into
mainfrom
security/deps-next-2026-10
Open

pollosp wants to merge 1 commit into
mainfrom
security/deps-next-2026-10

Conversation

@pollosp

@pollosp pollosp commented Oct 2, 2026

Copy link
Copy Markdown

Why

Dependabot reports a critical vulnerability in next: GHSA-vcvr-r3jv-pc5j (Remote Code Execution in next/og ImageResponse). Affected: >= 16.2.0, < 16.3.6. apps/web uses next@16.3.5.

The app code does not import next/og or ImageResponse (I searched apps/web and packages). The real exposure is thus low. But the alert is critical and the fix is a patch, so we must apply it.

Changes

Package From To Bump type Advisory Severity Alert #
next (direct, apps/web) 16.3.5 16.3.6 patch GHSA-vcvr-r3jv-pc5j (RCE in next/og ImageResponse) critical #430, #431
  • apps/web/package.json: "next": "16.3.5" -> "16.3.6" (exact pin, same as before).
  • The lockfile diff changes only next, @next/env and the @next/swc-* binaries (all 16.3.5 -> 16.3.6).
  • next@16.3.6 has no known advisory.
  • eslint-config-next stays at 16.3.5. No advisory affects it, and the lint config does not need to match the patch version.

Risk: medium

  • next is the framework of the web app. A patch release has a small risk of a regression in routing, rendering or the build.
  • This PR contains only next. Thus it is easy to revert alone.
  • Before merge, please check the Vercel preview: home page, login, chat and checkout.
  • Rollback: revert this PR (back to 16.3.5). No data or state changes.

How I tested

Local, Node 20.19.6, pnpm 10.33.0. Same steps as .github/workflows/ci.yml:

Command Result
pnpm install --frozen-lockfile pass
pnpm turbo run build --filter='./packages/*' --force pass
pnpm turbo run typecheck --force (includes next typegen) pass
pnpm turbo run test --force pass, 159 tests (same as main)
pnpm turbo run build --filter=@agent-commerce/web --force (CI placeholder env) pass
next start + curl on /, /login, /skill.md 200, no server errors
pnpm audit 0 critical (1 on main). The next finding is gone.

Not fixed in this PR

  • esbuild is in a separate low-risk PR. ws, @metamask/sdk and sharp are in a separate medium-risk PR.
  • These alerts need a major bump and are not done: image-size (#428, #429), valibot (#386, #422), fast-xml-parser (#391), stream-json (#426), uuid (#406, from the 8.x and 9.x copies). decode-uri-component (#425) needs 0.5.0. That version is ESM-only and breaks query-string@7.
  • No fix exists: node-forge (#432), elliptic (#387), bigint-buffer (#382).

🤖 Generated with Claude Code

Patch release that fixes GHSA-vcvr-r3jv-pc5j (RCE in next/og ImageResponse).
Lockfile changes only next, @next/env and @next/swc-* binaries.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
agent-commerce-sample-app Ready Ready Preview Oct 2, 2026 8:31am UTC

Request Review

This branch was successfully deployed

1 active deployment
Preview — 365199e5 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant