Skip to content

Upgrade Next.js to 15.5.27 (critical RCE advisories) - #121

Merged
ralyodio merged 1 commit into
masterfrom
chore/next-15.5.27
Oct 1, 2026
Merged

ralyodio merged 1 commit into
masterfrom
chore/next-15.5.27

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Pins next to 15.5.27 (was ^15.1.6, locked at 15.5.20). Stays on Next 15; no eslint-config-next or @next/* packages declared. bun.lock diff is only next, @next/env and the @next/swc-* binaries.

Advisories addressed:

Verified locally:

  • bun install --frozen-lockfile, bun run test (253 pass, 36 files), tsc --noEmit, bun run build (Next.js 15.5.27)
  • Booted the way the image runs it (bun run start, local file DB): / 200 with the same title as live; /robots.txt, /sitemap.xml, /favicon.ico 404 like live
  • OG route /api/og (next/og) returns a PNG, same as live
  • /_next/image?url=/assets/mascot-hero.png&w=256 200 image/png, same bytes as live

🤖 Generated with Claude Code

next pinned to 15.5.27 (was ^15.1.6 locked at 15.5.20). Fixes
GHSA-2xp9-vwfh-vxw4 (Image Optimization RCE).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednext@​15.5.20 ⏵ 15.5.2765 +13100 +7591 +19970

View full report

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

20 finding(s)

HIGH/CRITICAL: 3 | MEDIUM: 13 | LOW: 4

Severity Rule Location
HIGH sh-remote-script-execution public/install.sh:302
HIGH sh-remote-script-execution public/install.sh:305
HIGH sh-remote-script-execution public/install.sh:432
MEDIUM js-open-redirect app/dashboard/[[...tab]]/page.tsx:67
MEDIUM js-open-redirect app/signup/page.tsx:38
MEDIUM js-open-redirect components/PitSearch.tsx:118
MEDIUM js-unescaped-html-sink components/Tenant.tsx:21
MEDIUM js-unescaped-html-sink components/Tenant.tsx:22
MEDIUM js-unescaped-html-sink components/Tenant.tsx:62
MEDIUM js-unescaped-html-sink components/Tenant.tsx:136
MEDIUM sql-template-interpolation lib/db.ts:1117
MEDIUM sql-template-interpolation lib/db.ts:1147
MEDIUM redos-nested-quantifier lib/markdown.ts:109
MEDIUM sh-remote-script-execution public/install.sh:123
MEDIUM sh-remote-script-execution public/install.sh:127
MEDIUM sh-remote-script-execution public/install.sh:146
LOW secret-generic-credential tests/domain-webhook-active.test.mjs:18
LOW secret-generic-credential tests/domain-webhook-active.test.mjs:25
LOW secret-generic-credential tests/domain-webhook-active.test.mjs:30
LOW secret-generic-credential tests/project-webhook-management.test.mjs:53

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit e3a4bfb into master Oct 1, 2026
5 checks passed
@ralyodio
ralyodio deleted the chore/next-15.5.27 branch October 1, 2026 23:19
@ralyodio ralyodio mentioned this pull request Oct 1, 2026
ralyodio added a commit that referenced this pull request Oct 1, 2026
Patch release: Next.js 15.5.27 for the critical Image Optimization RCE
advisory (#121).

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant