Skip to content

[security] critical: 6 advisories in next #60

Description

@github-actions

Vulnerable package: next

6 critical/high advisory entries reported by pnpm audit.

Severity Title Vulnerable Patched Advisory
high Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale >=16.0.0 <16.2.11 >=16.2.11 1124170
high Next.js: Denial of Service in App Router using Server Actions >=16.0.0 <16.2.11 >=16.2.11 1124171
high Next.js: Server-Side Request Forgery in Server Actions on custom servers >=16.0.0 <16.2.11 >=16.2.11 1124184
high Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname >=16.0.0 <16.2.11 >=16.2.11 1124192
critical Next.js: Unauthenticated Remote Code Execution on windows-hosted servers >=16.0.0 <16.3.3 >=16.3.3 1193676
critical Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used >=16.0.0 <16.3.3 >=16.3.3 1193732

Suggested action

Run pnpm update next and verify with pnpm build. If the patched version is a major upgrade, check release notes for breaking changes first. Close this issue once the package is on a non-vulnerable version (the bot will re-open if new advisories appear).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions