Skip to content

fix: upgrade next to 15.5.15, 16.2.3 (GHSA-q4gf-8mx6-v5v3)#221

Open
orbisai0security wants to merge 3 commits intoshareAI-lab:mainfrom
orbisai0security:fix-ghsa-q4gf-8mx6-v5v3-next
Open

fix: upgrade next to 15.5.15, 16.2.3 (GHSA-q4gf-8mx6-v5v3)#221
orbisai0security wants to merge 3 commits intoshareAI-lab:mainfrom
orbisai0security:fix-ghsa-q4gf-8mx6-v5v3-next

Conversation

@orbisai0security
Copy link
Copy Markdown

Summary

Upgrade next from 16.1.6 to 15.5.15, 16.2.3 to fix GHSA-q4gf-8mx6-v5v3.

Vulnerability

Field Value
ID GHSA-q4gf-8mx6-v5v3
Severity HIGH
Scanner trivy
Rule GHSA-q4gf-8mx6-v5v3
File web/package-lock.json

Description: Next.js has a Denial of Service with Server Components

Changes

  • web/package.json
  • web/package-lock.json

Verification

  • Build passes
  • Scanner re-scan confirms fix
  • LLM code review passed

Automated security fix by OrbisAI Security

@vercel
Copy link
Copy Markdown

vercel Bot commented Apr 14, 2026

@orbisai0security is attempting to deploy a commit to the crazyboym's projects Team on Vercel.

A member of the Team first needs to authorize it.

@CrazyBoyM CrazyBoyM force-pushed the main branch 2 times, most recently from 36897b1 to d882d01 Compare April 14, 2026 16:11
@orbisai0security orbisai0security force-pushed the fix-ghsa-q4gf-8mx6-v5v3-next branch from 6cfdf5b to 9e87887 Compare April 16, 2026 04:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants