fix(web): next 16.3.5 -> 16.3.8, critical RCE in next/og ImageResponse - #80
Conversation
GHSA-vcvr-r3jv-pc5j, affecting 16.2.0-16.3.5. Surfaced on #79's CI run (unrelated PR, same dependency tree) and reproduced on main directly. This app doesn't use next/og or ImageResponse anywhere (grepped), so there was no live exploit path, but the fix is a zero-cost patch bump. Also picked up by the same npm audit fix: brace-expansion high (GHSA-q2hr-2g5m-vwhr / qhr7-859c-m2p7 / 6j4f-fj2g-mc7p), a transitive dev dependency via eslint's typescript-estree. Non-breaking. web/package.json pinned next as an exact version (no caret), which is why npm audit fix alone couldn't reach 16.3.8 -- bumped explicitly. Verified: web audit 0 high/critical (19 left, all moderate/low, same @stacks/connect-rooted set already documented as needing an upstream release). Fresh npm ci + next build clean, all 6 routes prerender. Root suite 258 passed / 1 expected fail (259), unaffected. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
unixwhisperer
left a comment
There was a problem hiding this comment.
Reviewed the full diff (49/49 lines, 2 files) -- clean and minimally scoped.
web/package.json: single line, next 16.3.5 -> ^16.3.8.
web/package-lock.json: lockfile regeneration for next + all @next/* platform binaries to 16.3.8. No unrelated dependency changes.
Confirms this fixes both failing findings, not just the one in the title:
- Critical (the stated fix): Next.js RCE in
next/og ImageResponse, GHSA-vcvr-r3jv-pc5j, affects 16.2.0-16.3.5. - High (bonus, not called out in the PR description): bumping
nextalso pulledbrace-expansionpast its vulnerable range transitively -- root copy 1.1.18 -> 1.1.21, and the nested copy under@typescript-eslint/typescript-estree5.0.9 -> 5.0.12. Both were in the vulnerable ranges npm audit flagged (<=1.1.20and4.0.0 - 5.0.11).
Verified on this PR's own CI run that Dependency Audit (web) is clean, which is the direct proof -- our --audit-level=high gate only fails on high/critical, and this run has neither anymore. The remaining moderate/low findings (decode-uri-component, elliptic, the WalletConnect chain) are unaffected by this PR and intentionally below the gate threshold; separate matter if we want those addressed.
This also explains every red "Security Scan" run on main since this was opened (#77's merge, #79's merge) -- unrelated to those PRs, same pre-existing root cause both times. Nothing else is needed from this side; merging this clears the gate.
Approving.
Summary
GHSA-vcvr-r3jv-pc5j, critical RCE in
next/og'sImageResponse, affecting 16.2.0–16.3.5 (currently pinned). Surfaced on #79's CI (an unrelated PR sharing the dependency tree) and reproduced directly onmain.This app doesn't use
next/ogorImageResponseanywhere — greppedsrc//app/, nothing. So there's no live exploit path today, but the fix is a zero-cost patch bump, no reason to leave it.Also fixed, same
npm audit fixpassbrace-expansionhigh (GHSA-q2hr-2g5m-vwhr / qhr7-859c-m2p7 / 6j4f-fj2g-mc7p), transitive via eslint'stypescript-estree. Non-breaking.Why an explicit bump was needed
web/package.jsonpinsnextas an exact version (no caret), sonpm audit fixalone couldn't reach 16.3.8 — it's "outside the stated range" until bumped explicitly, which this does.Verification
@stacks/connect-rooted set needing an upstream release).npm ci+next build: clean, all 6 routes prerender.🤖 Generated with Claude Code