security: bump next to 16.3.8 (next/og ImageResponse RCE) - #27
Open
SaulBuilds wants to merge 1 commit into
Open
SaulBuilds wants to merge 1 commit into
SaulBuilds wants to merge 1 commit into
Conversation
next ^16.3.3 (lock 16.3.3) -> ^16.3.8 (lock 16.3.8); @next/env and @next/swc-* follow. Lockfile regenerated with npm 11 --package-lock-only (preserves libc fields); the only other lock delta is metadata for tailwind's optional bundled oxide-wasm32-wasi deps, no version changes. Verified locally: npm ci, npm audit (prod and full) 0 vulnerabilities, tsc --noEmit, vitest (110 passed, 4 skipped), next build + postbuild verify:bundle gates all pass. content-lint --strict fails on a pre-existing stale generated addresses page, unrelated to this bump. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Vv2gVzy5XLFKg48yckN9YQ
BerryManifold
approved these changes
Oct 2, 2026
BerryManifold
left a comment
Contributor
There was a problem hiding this comment.
Approved on current head 1555fc7 for the urgent public-site Next RCE bump. Diff is scoped to next/@next 16.3.8 plus lockfile metadata. Merge is still blocked by the pre-existing stale generated addresses content-lint; run docs:addresses or otherwise refresh that generated page before merge.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Advisory
Critical Next.js advisory: Remote Code Execution in
next/ogImageResponse, vulnerable>=16.2.0 <16.3.6. Owner approved bumping to16.3.8.Change
next:^16.3.3(lockfile 16.3.3 — vulnerable) →^16.3.8(lockfile 16.3.8)@next/envand@next/swc-*follow to 16.3.8. Noeslint-config-next/ other@next/*deps in this repo.npm@11 install --package-lock-only(npm 10 would have stripped existinglibcfields). The only non-next lock delta is added metadata for@tailwindcss/oxide-wasm32-wasi's optional bundled deps (dev/optional/inBundle) — no resolved version changes besides next.Exposure in this repo
Yes — uses
ImageResponseon the public site:app/opengraph-image.tsximportsImageResponsefromnext/og.Verification (local, mirrors
.github/workflows/ci.yml)npm ci✅npm audit --omit=dev --audit-level=high✅ 0 vulnerabilities (fullnpm audit --audit-level=highalso 0)npm run typecheck✅npm test✅ 110 passed, 4 skippednpm run build(next build+ postbuild gates) ✅npm run verify:bundle✅npm run content-lint -- --strict❌ pre-existing, unrelated: truth-lint flagscontent/chain/_generated/addresses.mdas generated from an older address book (needsnpm run docs:addresses). Not touched by this PR.Do not deploy from this PR branch; merge then deploy from main.
🤖 Generated with Claude Code
https://claude.ai/code/session_01Vv2gVzy5XLFKg48yckN9YQ