Vulnerable package: next
6 critical/high advisory entries reported by pnpm audit.
| Severity |
Title |
Vulnerable |
Patched |
Advisory |
| high |
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale |
>=16.0.0 <16.2.11 |
>=16.2.11 |
1124170 |
| high |
Next.js: Denial of Service in App Router using Server Actions |
>=16.0.0 <16.2.11 |
>=16.2.11 |
1124171 |
| high |
Next.js: Server-Side Request Forgery in Server Actions on custom servers |
>=16.0.0 <16.2.11 |
>=16.2.11 |
1124184 |
| high |
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname |
>=16.0.0 <16.2.11 |
>=16.2.11 |
1124192 |
| critical |
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers |
>=16.0.0 <16.3.3 |
>=16.3.3 |
1193676 |
| critical |
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used |
>=16.0.0 <16.3.3 |
>=16.3.3 |
1193732 |
Suggested action
Run pnpm update next and verify with pnpm build. If the patched version is a major upgrade, check release notes for breaking changes first. Close this issue once the package is on a non-vulnerable version (the bot will re-open if new advisories appear).
Vulnerable package:
next6 critical/high advisory entries reported by
pnpm audit.>=16.0.0 <16.2.11>=16.2.11>=16.0.0 <16.2.11>=16.2.11>=16.0.0 <16.2.11>=16.2.11>=16.0.0 <16.2.11>=16.2.11>=16.0.0 <16.3.3>=16.3.3>=16.0.0 <16.3.3>=16.3.3Suggested action
Run
pnpm update nextand verify withpnpm build. If the patched version is a major upgrade, check release notes for breaking changes first. Close this issue once the package is on a non-vulnerable version (the bot will re-open if new advisories appear).