Skip to content

fix(deps): Next.js 16.3.8 for the next/og RCE, plus patched source-map-js and brace-expansion - #77

Merged
kevincodex1 merged 1 commit into
mainfrom
fix/next-16.3.6
Oct 6, 2026
Merged

kevincodex1 merged 1 commit into
mainfrom
fix/next-16.3.6

Conversation

@Vasanthdev2004

@Vasanthdev2004 Vasanthdev2004 commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Security update for the open Dependabot alerts on main.

Alert Severity Package Fix
#10 GHSA-vcvr-r3jv-pc5j critical next 16.3.4: remote code execution in next/og ImageResponse 16.3.8
#12 GHSA-68fv-2mgg-jv7q high source-map-js 1.2.1: event-loop denial of service 1.2.2
#9, #8 GHSA-q2hr-2g5m-vwhr medium brace-expansion 1.1.18 and 5.0.9: CPU denial of service 1.1.21, 5.0.12

The Next.js one is the urgent part: the site's share cards (app/opengraph-image.tsx, app/t/[chain]/[token]/opengraph-image.tsx) are rendered with ImageResponse, and the token card draws creator-chosen names and symbols.

What changes: next and eslint-config-next 16.3.4 → 16.3.8 (with Next's platform binaries); source-map-js and brace-expansion move to their patched releases inside the ranges their dependents already allow. Lockfile only for those three; nothing else moves.

Checks: lint (0 errors), tsc --noEmit, npm test (844 pass, 0 fail, 10 skipped), next build. On next start, the home and token share cards both render (200, image/png).

Notes

Summary by CodeRabbit

  • Chores
    • Updated the versions of Next.js and its ESLint configuration.

…p-js and brace-expansion

next >= 16.2.0 < 16.3.6 has remote code execution in next/og ImageResponse (GHSA-vcvr-r3jv-pc5j); the share cards are rendered with it and the token card draws creator-chosen names and symbols. Also lifts source-map-js to 1.2.2 (GHSA-68fv-2mgg-jv7q) and brace-expansion to 1.1.21 / 5.0.12 (GHSA-q2hr-2g5m-vwhr) inside their existing ranges.
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 3ff725ca-9f03-488b-9bc3-627cd344c7c8
📥 Commits

Reviewing files that changed from the base of the PR and between 7c9a88e and 6d3e16c.

⛔ Files ignored due to path filters (1)
  • app/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • app/package.json

Included review availability: This review used your included allowance. 3 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

The app package manifest updates the next dependency and eslint-config-next devDependency ranges from ^16.3.4 to ^16.3.8.

Changes

Next.js Dependency Updates

Layer / File(s) Summary
Update Next.js version ranges
app/package.json
The next dependency and eslint-config-next devDependency ranges changed from ^16.3.4 to ^16.3.8.

Priority: ⬆️ High

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested reviewers: kevincodex1, beardthelion

Merge Risk: ⚪ Minimal · up to 6d3e1

The lockfile selects Next.js 16.3.8 and the updated transitive dependency versions, with no introduced user-facing or deployment risk evident.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the dependency updates and names the Next.js security fix and the patched transitive dependencies.
Linked Issues check ✅ Passed Issue #10 is closed and completed, so it provides historical context only. No active directly linked issue supplies coding requirements for this pull request.
Out of Scope Changes check ✅ Passed The current description and whole-PR summary identify dependency updates for Next.js, source-map-js, and brace-expansion as fixes for open security alerts. The visible package.json changes update next…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@kevincodex1
kevincodex1 merged commit 44cab6d into main Oct 6, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants