Skip to content

Upgrade Next.js to 15.5.27 (critical RCE advisories) - #175

Merged
ralyodio merged 1 commit into
masterfrom
chore/next-15.5.27
Oct 1, 2026
Merged

ralyodio merged 1 commit into
masterfrom
chore/next-15.5.27

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Pins next and eslint-config-next to 15.5.27 in apps/web (was next ^15.1.6, locked at 15.5.20). Stays on Next 15. Nothing else changes: the bun.lock diff is only next, eslint-config-next, @next/env, @next/eslint-plugin-next and the @next/swc-* binaries.

Advisories addressed:

Verified locally:

  • bun install --frozen-lockfile, bun run typecheck, bun run test (38 files, 192 tests), bun run build (Next.js 15.5.27)
  • Booted the way the dev2 image runs it (bun --bun next start, local file DB, migrate + seeds; media daemon not started): /, /leaderboard, /rss.xml, /robots.txt, /sitemap.xml, /opengraph-image all 200, same as live; OG image is a PNG; same page title as live
  • /_next/image?url=<unsplash>&w=256 200 image/jpeg, identical byte size to live; invalid width 400 like live

🤖 Generated with Claude Code

next and eslint-config-next pinned to 15.5.27 (was next ^15.1.6 locked at
15.5.20). Fixes GHSA-2xp9-vwfh-vxw4 (Image Optimization RCE); the image
optimizer here accepts any https host.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

11 finding(s)

MEDIUM: 9 | LOW: 2

Severity Rule Location
MEDIUM js-unescaped-html-sink apps/web/app/about/page.tsx:40
MEDIUM sql-template-interpolation apps/web/app/api/admin/media/[id]/route.ts:30
MEDIUM sql-template-interpolation apps/web/app/api/admin/tags/[id]/route.ts:22
MEDIUM sql-template-interpolation apps/web/app/api/admin/users/[id]/route.ts:23
MEDIUM js-unescaped-html-sink apps/web/app/layout.tsx:56
MEDIUM js-unescaped-html-sink apps/web/app/pricing/page.tsx:17
MEDIUM js-unescaped-html-sink apps/web/components/NewsletterComposer.tsx:87
MEDIUM sql-template-interpolation apps/web/lib/queries.ts:169
MEDIUM sql-template-interpolation apps/web/lib/rewards.ts:198
LOW sql-template-interpolation apps/web/lib/rewards.test.ts:86
LOW js-unescaped-html-sink docs/design_handoff_aiornot_vote/image-slot.js:455

Snippets are redacted; ThreatCrush never prints matched credential material.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedeslint-config-next@​15.5.20 ⏵ 15.5.2799 +11006598100
Updatednext@​15.5.20 ⏵ 15.5.2765 +13100 +7591 +19970

View full report

@ralyodio
ralyodio merged commit cf12deb into master Oct 1, 2026
7 checks passed
@ralyodio
ralyodio deleted the chore/next-15.5.27 branch October 1, 2026 23:05
@ralyodio ralyodio mentioned this pull request Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant