Skip to content

fix(web): next 16.3.5 -> 16.3.8, critical RCE in next/og ImageResponse - #80

Merged
mattglory merged 1 commit into
mainfrom
fix-next-critical-rce
Oct 1, 2026
Merged

mattglory merged 1 commit into
mainfrom
fix-next-critical-rce

Conversation

@mattglory

Copy link
Copy Markdown
Owner

Summary

GHSA-vcvr-r3jv-pc5j, critical RCE in next/og's ImageResponse, affecting 16.2.0–16.3.5 (currently pinned). Surfaced on #79's CI (an unrelated PR sharing the dependency tree) and reproduced directly on main.

This app doesn't use next/og or ImageResponse anywhere — grepped src//app/, nothing. So there's no live exploit path today, but the fix is a zero-cost patch bump, no reason to leave it.

Also fixed, same npm audit fix pass

brace-expansion high (GHSA-q2hr-2g5m-vwhr / qhr7-859c-m2p7 / 6j4f-fj2g-mc7p), transitive via eslint's typescript-estree. Non-breaking.

Why an explicit bump was needed

web/package.json pins next as an exact version (no caret), so npm audit fix alone couldn't reach 16.3.8 — it's "outside the stated range" until bumped explicitly, which this does.

Verification

  • Web audit: 0 high/critical (19 left, all moderate/low — the already-documented @stacks/connect-rooted set needing an upstream release).
  • Fresh npm ci + next build: clean, all 6 routes prerender.
  • Root suite: 258 passed / 1 expected fail (259), unaffected.

🤖 Generated with Claude Code

GHSA-vcvr-r3jv-pc5j, affecting 16.2.0-16.3.5. Surfaced on #79's CI run
(unrelated PR, same dependency tree) and reproduced on main directly.
This app doesn't use next/og or ImageResponse anywhere (grepped), so
there was no live exploit path, but the fix is a zero-cost patch bump.

Also picked up by the same npm audit fix: brace-expansion high
(GHSA-q2hr-2g5m-vwhr / qhr7-859c-m2p7 / 6j4f-fj2g-mc7p), a transitive
dev dependency via eslint's typescript-estree. Non-breaking.

web/package.json pinned next as an exact version (no caret), which is
why npm audit fix alone couldn't reach 16.3.8 -- bumped explicitly.

Verified: web audit 0 high/critical (19 left, all moderate/low, same
@stacks/connect-rooted set already documented as needing an upstream
release). Fresh npm ci + next build clean, all 6 routes prerender.
Root suite 258 passed / 1 expected fail (259), unaffected.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
web Ready Ready Preview Oct 1, 2026 12:03am UTC

Request Review

@unixwhisperer unixwhisperer left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the full diff (49/49 lines, 2 files) -- clean and minimally scoped.

web/package.json: single line, next 16.3.5 -> ^16.3.8.
web/package-lock.json: lockfile regeneration for next + all @next/* platform binaries to 16.3.8. No unrelated dependency changes.

Confirms this fixes both failing findings, not just the one in the title:

  • Critical (the stated fix): Next.js RCE in next/og ImageResponse, GHSA-vcvr-r3jv-pc5j, affects 16.2.0-16.3.5.
  • High (bonus, not called out in the PR description): bumping next also pulled brace-expansion past its vulnerable range transitively -- root copy 1.1.18 -> 1.1.21, and the nested copy under @typescript-eslint/typescript-estree 5.0.9 -> 5.0.12. Both were in the vulnerable ranges npm audit flagged (<=1.1.20 and 4.0.0 - 5.0.11).

Verified on this PR's own CI run that Dependency Audit (web) is clean, which is the direct proof -- our --audit-level=high gate only fails on high/critical, and this run has neither anymore. The remaining moderate/low findings (decode-uri-component, elliptic, the WalletConnect chain) are unaffected by this PR and intentionally below the gate threshold; separate matter if we want those addressed.

This also explains every red "Security Scan" run on main since this was opened (#77's merge, #79's merge) -- unrelated to those PRs, same pre-existing root cause both times. Nothing else is needed from this side; merging this clears the gate.

Approving.

@mattglory
mattglory merged commit e4473a2 into main Oct 1, 2026
7 checks passed
@mattglory
mattglory deleted the fix-next-critical-rce branch October 1, 2026 01:20

This branch was successfully deployed

1 active deployment
Preview — f039711b Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants