chore(deps): update dependency next to v16.3.6 [security] - #8599
renovate[bot] wants to merge 1 commit into
Conversation
|
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
View your CI Pipeline Execution ↗ for commit 1b78e84 ☁️ Nx Cloud last updated this comment at |
This PR contains the following updates:
16.3.4→16.3.6Next.js: Remote Code Execution in next/og ImageResponse
GHSA-vcvr-r3jv-pc5j
More information
Details
Impact
The Node.js
ImageResponseimplementation fromnext/ogis affected by an upstream vulnerability. This can lead to remote code execution.Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation:
Applications using the Edge
ImageResponseimplementation, or applications that do not pass attacker-controlled values into SVG content, attributes, or styles, are not affected.Workaround
If upgrading is not immediately possible, do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js
ImageResponseimplementation fromnext/og.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
vercel/next.js (next)
v16.3.6Compare Source
v16.3.5Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.