[Aikido] Fix security issue in next via minor version upgrade from 15.4.8 to 15.5.21 - #760
Open
aikido-autofix[bot] wants to merge 1 commit into
Open
Conversation
✅ Security Analysis ResultsNo security issues found. 3 files reviewed.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upgrade Next.js to fix SSRF via WebSocket requests, connection exhaustion DoS, and multiple CPU exhaustion DoS vulnerabilities in App Router endpoints.
✅ Code not affected by breaking changes.
✅ No breaking changes from the Next.js 15.4.8 → 15.5.16 upgrade affect this codebase. The demo-nextjs package uses only basic Next.js features (Pages Router and App Router with standard components) and does not utilize any of the experimental features, MDX, AMP, middleware, or advanced APIs (
cookies(),headers()) that are affected by the breaking changes in version 15.5.0.All breaking changes by upgrading next from version 15.4.8 to 15.5.21 (CHANGELOG)
experimental.strictNextHead: #81882window.next.turbopackinstead: #82580✅ 7 CVEs resolved by this upgrade
This PR will resolve the following CVEs:
🤖 Remediation details
Upgrade
nextto patch multiple high/medium severity vulnerabilitiesShort summary
This PR remediates multiple high- and medium-severity vulnerabilities in the
nextpackage by upgrading it to15.5.21. The change is applied in two places: the rootpackage.json(devDependencies) and thepackages/demo-nextjsworkspace member manifest (dependencies). The sharedyarn.lockat the repository root is refreshed to resolve a singlenextentry at the patched version, replacing the previously pinned15.4.8.next
nextwas declared as an exact-pinned direct dependency in both the rootpackage.json(devDependencies) and thepackages/demo-nextjsworkspacepackage.json(dependencies), both at15.4.8. Because Yarn Classic uses a single shared lockfile for the monorepo, both manifest entries had to be updated together; leaving either at15.4.8kept a stale lockfile entry for the vulnerable version. The target version15.5.21is the smallest15.xrelease that satisfies the patched-version floor for all advisories in scope, including CVE-2026-64644 (fixed in15.5.21) which sits above the intermediate15.5.16floor required by the other advisories.Version changes
next15.4.815.5.21packages/demo-nextjsdependencies)