Skip to content

chore(deps): update dependency next to v16.3.6 [security] - #36

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/npm-next-vulnerability
Oct 1, 2026
Merged

renovate[bot] merged 1 commit into
masterfrom
renovate/npm-next-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
next (source) 16.3.3 → 16.3.6 age confidence

Next.js: Remote Code Execution in next/og ImageResponse

GHSA-vcvr-r3jv-pc5j

More information

Details

Impact

The Node.js ImageResponse implementation from next/og is affected by an upstream vulnerability. This can lead to remote code execution.

Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation:

import { ImageResponse } from 'next/og'

export async function GET(request: Request) {
  const value = new URL(request.url).searchParams.get('value') ?? ''

  return new ImageResponse(
    <svg width="1200" height="630">
      <title>{value}</title>
    </svg>
  )
}

Applications using the Edge ImageResponse implementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected.

Workaround

If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js ImageResponse implementation from next/og.

Severity

  • CVSS Score: 9.5 / 10 (Critical)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

vercel/next.js (next)

v16.3.6

Compare Source

v16.3.5

Compare Source

v16.3.4

Compare Source


Configuration

📅 Schedule: (in timezone America/Chicago)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the security label Sep 30, 2026
@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
rdap Ready Ready Preview Sep 30, 2026 9:16pm UTC

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 0f272714-2191-4803-9928-1c2659e1e382

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov-commenter

codecov-commenter commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 95.58%. Comparing base (c78c5be) to head (05ff7f1).

Additional details and impacted files
@@           Coverage Diff           @@
##           master      #36   +/-   ##
=======================================
  Coverage   95.58%   95.58%           
=======================================
  Files          16       16           
  Lines         657      657           
  Branches      207      207           
=======================================
  Hits          628      628           
  Misses         29       29           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate
renovate Bot merged commit 77f116d into master Oct 1, 2026
9 checks passed
@renovate
renovate Bot deleted the renovate/npm-next-vulnerability branch October 1, 2026 16:00

This branch was successfully deployed

1 active deployment
Preview — 05ff7f18 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant