Skip to content

fix: bump next peerDependency to ^15.5.7 (GHSA-9qr9-h5gf-34mp)#26

Merged
dcbouius merged 1 commit intomainfrom
fix/next-security-vulnerability
Apr 1, 2026
Merged

fix: bump next peerDependency to ^15.5.7 (GHSA-9qr9-h5gf-34mp)#26
dcbouius merged 1 commit intomainfrom
fix/next-security-vulnerability

Conversation

@dcbouius
Copy link
Copy Markdown
Contributor

@dcbouius dcbouius commented Apr 1, 2026

Summary

  • Bumps the next peerDependency floor from ^15.2.3 to ^15.5.7 to exclude versions vulnerable to RCE via the React flight protocol
  • ^14.2.25 range is unaffected (advisory targets >= 15.5.0-canary.0)

Advisory



Next.js versions >= 15.5.0-canary.0 and < 15.5.7 are vulnerable to RCE
via the React flight protocol. Raising the peerDependency floor to
^15.5.7 ensures consumers are not using affected versions.
@dcbouius dcbouius requested a review from cdbartholomew April 1, 2026 17:00
@dcbouius dcbouius merged commit f7dee47 into main Apr 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants