Skip to content

security: bump next to 16.3.8 (next/og ImageResponse RCE) - #27

Open
SaulBuilds wants to merge 1 commit into
mainfrom
security/next-16.3.8
Open

SaulBuilds wants to merge 1 commit into
mainfrom
security/next-16.3.8

Conversation

@SaulBuilds

Copy link
Copy Markdown
Contributor

Advisory

Critical Next.js advisory: Remote Code Execution in next/og ImageResponse, vulnerable >=16.2.0 <16.3.6. Owner approved bumping to 16.3.8.

Change

  • next: ^16.3.3 (lockfile 16.3.3 — vulnerable) → ^16.3.8 (lockfile 16.3.8)
  • @next/env and @next/swc-* follow to 16.3.8. No eslint-config-next / other @next/* deps in this repo.
  • Lockfile regenerated with npm@11 install --package-lock-only (npm 10 would have stripped existing libc fields). The only non-next lock delta is added metadata for @tailwindcss/oxide-wasm32-wasi's optional bundled deps (dev/optional/inBundle) — no resolved version changes besides next.

Exposure in this repo

Yes — uses ImageResponse on the public site: app/opengraph-image.tsx imports ImageResponse from next/og.

Verification (local, mirrors .github/workflows/ci.yml)

  • npm ci ✅
  • npm audit --omit=dev --audit-level=high ✅ 0 vulnerabilities (full npm audit --audit-level=high also 0)
  • npm run typecheck ✅
  • npm test ✅ 110 passed, 4 skipped
  • npm run build (next build + postbuild gates) ✅
  • npm run verify:bundle ✅
  • npm run content-lint -- --strict ❌ pre-existing, unrelated: truth-lint flags content/chain/_generated/addresses.md as generated from an older address book (needs npm run docs:addresses). Not touched by this PR.

Do not deploy from this PR branch; merge then deploy from main.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Vv2gVzy5XLFKg48yckN9YQ

next ^16.3.3 (lock 16.3.3) -> ^16.3.8 (lock 16.3.8); @next/env and
@next/swc-* follow. Lockfile regenerated with npm 11 --package-lock-only
(preserves libc fields); the only other lock delta is metadata for
tailwind's optional bundled oxide-wasm32-wasi deps, no version changes.

Verified locally: npm ci, npm audit (prod and full) 0 vulnerabilities,
tsc --noEmit, vitest (110 passed, 4 skipped), next build + postbuild
verify:bundle gates all pass. content-lint --strict fails on a
pre-existing stale generated addresses page, unrelated to this bump.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Vv2gVzy5XLFKg48yckN9YQ
@SaulBuilds
SaulBuilds requested a review from a team as a code owner October 1, 2026 23:11

@BerryManifold BerryManifold left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved on current head 1555fc7 for the urgent public-site Next RCE bump. Diff is scoped to next/@next 16.3.8 plus lockfile metadata. Merge is still blocked by the pre-existing stale generated addresses content-lint; run docs:addresses or otherwise refresh that generated page before merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants