Conversation
Patch release that fixes GHSA-vcvr-r3jv-pc5j (RCE in next/og ImageResponse). Lockfile changes only next, @next/env and @next/swc-* binaries. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Dependabot reports a critical vulnerability in
next: GHSA-vcvr-r3jv-pc5j (Remote Code Execution innext/ogImageResponse). Affected:>= 16.2.0, < 16.3.6.apps/webusesnext@16.3.5.The app code does not import
next/ogorImageResponse(I searchedapps/webandpackages). The real exposure is thus low. But the alert is critical and the fix is a patch, so we must apply it.Changes
apps/web)apps/web/package.json:"next": "16.3.5"->"16.3.6"(exact pin, same as before).next,@next/envand the@next/swc-*binaries (all 16.3.5 -> 16.3.6).next@16.3.6has no known advisory.eslint-config-nextstays at 16.3.5. No advisory affects it, and the lint config does not need to match the patch version.Risk: medium
nextis the framework of the web app. A patch release has a small risk of a regression in routing, rendering or the build.next. Thus it is easy to revert alone.How I tested
Local, Node 20.19.6, pnpm 10.33.0. Same steps as
.github/workflows/ci.yml:pnpm install --frozen-lockfilepnpm turbo run build --filter='./packages/*' --forcepnpm turbo run typecheck --force(includesnext typegen)pnpm turbo run test --forcemain)pnpm turbo run build --filter=@agent-commerce/web --force(CI placeholder env)next start+curlon/,/login,/skill.mdpnpm auditmain). Thenextfinding is gone.Not fixed in this PR
esbuildis in a separate low-risk PR.ws,@metamask/sdkandsharpare in a separate medium-risk PR.image-size(#428, #429),valibot(#386, #422),fast-xml-parser(#391),stream-json(#426),uuid(#406, from the 8.x and 9.x copies).decode-uri-component(#425) needs 0.5.0. That version is ESM-only and breaksquery-string@7.node-forge(#432),elliptic(#387),bigint-buffer(#382).🤖 Generated with Claude Code