Skip to content

fix(deps): bump next to ^16.3.3 in web, patches GHSA-p293-qw3h-jr36 - #1668

Open
aniruddhaadak80 wants to merge 1 commit into
supermemoryai:mainfrom
aniruddhaadak80:fix/security-next-ghsa-p293
Open

aniruddhaadak80 wants to merge 1 commit into
supermemoryai:mainfrom
aniruddhaadak80:fix/security-next-ghsa-p293

Conversation

@aniruddhaadak80

Copy link
Copy Markdown

Summary\nPatches GHSA-p293-qw3h-jr36 (CVE-2026-75604, critical 9.0): unauthenticated RCE via path traversal on Windows-hosted Next.js servers. No workaround exists.\n\nFollows up #1655, which bumped chatapp, sdk-playground and memory-graph-playground but missed \�pps/web.\n\n## Change\n- \�pps/web/package.json: \

ext ^16.0.11\ -> ^16.3.3\ (affected range was >=16.0 <16.3.3\)\n- \�un.lock\ regenerated via \�un install --lockfile-only\ (resolves next 16.3.4)\n\n## Verification\n- Lockfile resolves next 16.3.4 (>= patched 16.3.3)\n\nAdvisory: GHSA-p293-qw3h-jr36

GHSA-p293-qw3h-jr36 (CVE-2026-75604, critical): unauthenticated RCE on Windows-hosted Next.js servers. apps/web was on ^16.0.11 (affected: >=16.0 <16.3.3). bun.lock regenerated (resolves next 16.3.4). Follows up supermemoryai#1655, which covered chatapp, sdk-playground and memory-graph-playground but missed web.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant