Skip to content

Update npm package next to v15.5.24 [SECURITY] - #9610

Open
hash-dependencies[bot] wants to merge 1 commit into
mainfrom
deps/js/npm-next-vulnerability
Open

Update npm package next to v15.5.24 [SECURITY]#9610
hash-dependencies[bot] wants to merge 1 commit into
mainfrom
deps/js/npm-next-vulnerability

Conversation

@hash-dependencies

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
next (source) 15.5.2115.5.24 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

CVE-2026-75604 / GHSA-p293-qw3h-jr36

More information

Details

Impact

A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.

Workaround

There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.

Severity

  • CVSS Score: 9.0 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

GHSA-2xp9-vwfh-vxw4

More information

Details

A vulnerability in the underlying libheif library used by sharp which Next.js uses for image optimization can lead to remote code execution when AVIF files are optimized.

Until a fix has propagated, optimization of AVIF files is disabled.

Severity

  • CVSS Score: 9.5 / 10 (Critical)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

vercel/next.js (next)

v15.5.24

Compare Source

This release contains security fixes for the following advisories:

Critical:

v15.5.23

Compare Source

What's Changed

Full Changelog: vercel/next.js@v15.5.22...v15.5.23

v15.5.22

Compare Source

What's Changed

Full Changelog: vercel/next.js@v15.5.21...v15.5.22


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • "before 4am every weekday,every weekend"

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@vercel

vercel Bot commented Sep 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
hash Error Error Sep 9, 2026 7:26am UTC
3 Skipped Deployments
Project Deployment Actions Updated
hashdotdesign-tokens Ignored Ignored Sep 9, 2026 7:26am UTC
petrinaut Skipped Skipped Sep 9, 2026 7:26am UTC
petrinaut-docs Skipped Skipped Sep 9, 2026 7:26am UTC

Request Review

@hash-dependencies

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: yarn.lock
➤ YN0000: · Yarn 4.16.0
➤ YN0000: ┌ Project validation
➤ YN0057: │ @apps/plugin-browser: 'nohoist' is deprecated, please use 'installConfig.hoistingLimits' instead
➤ YN0000: └ Completed
➤ YN0000: ┌ Resolution step
➤ YN0085: │ + next@npm:15.5.24, @next/env@npm:15.5.24, @next/swc-darwin-arm64@npm:15.5.24, @next/swc-darwin-x64@npm:15.5.24, @next/swc-linux-arm64-gnu@npm:15.5.24, and 5 more.
➤ YN0000: └ Completed in 2s 145ms
➤ YN0000: ┌ Post-resolution validation
➤ YN0060: │ @astrojs/markdown-remark is listed by your project with version 7.2.4 (ped3581), which doesn't satisfy what astro and other dependencies request (7.2.2).
➤ YN0060: │ @types/react is listed by your project with version 19.2.14 (p99e71d), which doesn't satisfy what react-remove-scroll (via @tldraw/tldraw) and other dependencies request (but they have non-overlapping ranges!).
➤ YN0060: │ eslint is listed by your project with version 9.39.4 (p88bec7), which doesn't satisfy what eslint-config-airbnb and other dependencies request (but they have non-overlapping ranges!).
➤ YN0060: │ eslint-plugin-react-hooks is listed by your project with version 7.0.1 (p699002), which doesn't satisfy what eslint-config-airbnb requests (^4.3.0).
➤ YN0060: │ graphology is listed by your project with version 0.26.0 (p418068), which doesn't satisfy what @react-sigma/core requests (~0.25.4).
➤ YN0060: │ react is listed by your project with version 19.2.6 (p297d1e), which doesn't satisfy what material-ui-popup-state and other dependencies request (but they have non-overlapping ranges!).
➤ YN0060: │ react is listed by your project with version 19.2.6 (p327a01), which doesn't satisfy what react-inspector (via @hashintel/ds-components) and other dependencies request (but they have non-overlapping ranges!).
➤ YN0060: │ react is listed by your project with version 19.2.6 (p53dd30), which doesn't satisfy what react-inspector (via @ladle/react) and other dependencies request (but they have non-overlapping ranges!).
➤ YN0060: │ react is listed by your project with version 19.2.6 (p5a9f3c), which doesn't satisfy what @apollo/client and other dependencies request (but they have non-overlapping ranges!).
➤ YN0060: │ react is listed by your project with version 19.2.6 (p656648), which doesn't satisfy what react-inspector (via @hashintel/ds-components) and other dependencies request (but they have non-overlapping ranges!).
➤ YN0060: │ react is listed by your project with version 19.2.6 (p9bfa18), which doesn't satisfy what react-inspector (via @hashintel/ds-components) and other dependencies request (but they have non-overlapping ranges!).
➤ YN0060: │ react is listed by your project with version 19.2.6 (pb2c0b1), which doesn't satisfy what @apollo/client and other dependencies request (but they have non-overlapping ranges!).
➤ YN0060: │ react-dom is listed by your project with version 19.2.6 (pbfb936), which doesn't satisfy what @apollo/client and other dependencies request (but they have non-overlapping ranges!).
➤ YN0060: │ react-hook-form is listed by your project with version 7.65.0 (pf60118), which doesn't satisfy what @hashintel/query-editor and other dependencies request (7.61.1).
➤ YN0060: │ storybook is listed by your project with version 9.1.19 (p14b1b3), which doesn't satisfy what eslint-plugin-storybook requests (^10.3.1).
➤ YN0060: │ storybook is listed by your project with version 9.1.19 (pa824a9), which doesn't satisfy what eslint-plugin-storybook requests (^10.3.1).
➤ YN0060: │ storybook is listed by your project with version 9.1.19 (pcf516a), which doesn't satisfy what eslint-plugin-storybook requests (^10.3.1).
➤ YN0060: │ storybook is listed by your project with version 9.1.19 (pf24719), which doesn't satisfy what eslint-plugin-storybook requests (^10.3.1).
➤ YN0060: │ type-fest is listed by your project with version 5.3.1 (pf96305), which doesn't satisfy what @pmmmwh/react-refresh-webpack-plugin requests (>=0.17.0 <5.0.0).
➤ YN0060: │ vitest is listed by your project with version 4.1.10 (p1105ba), which doesn't satisfy what @effect/vitest and other dependencies request (but they have non-overlapping ranges!).
➤ YN0060: │ zod is listed by your project with version 4.4.3 (p3cb446), which doesn't satisfy what zod-to-json-schema and other dependencies request (^3.25.0).
➤ YN0002: │ @apps/brunch-agent@workspace:apps/brunch-agent doesn't provide zod (p783fc3), requested by @anthropic-ai/sdk and other dependencies.
➤ YN0002: │ @apps/hash-ai-worker-ts@workspace:apps/hash-ai-worker-ts doesn't provide @llamaindex/core (p84f0aa), requested by @llamaindex/readers.
➤ YN0002: │ @apps/hash-ai-worker-ts@workspace:apps/hash-ai-worker-ts doesn't provide @llamaindex/env (p06d4a4), requested by @llamaindex/readers.
➤ YN0002: │ @apps/hash-ai-worker-ts@workspace:apps/hash-ai-worker-ts doesn't provide react (p686178), requested by @blockprotocol/core and other dependencies.
➤ YN0002: │ @apps/hash-api@workspace:apps/hash-api doesn't provide react (p7e58b9), requested by @blockprotocol/core and other dependencies.
➤ YN0002: │ @apps/hash-frontend@workspace:apps/hash-frontend doesn't provide @codemirror/view (pc99a9f), requested by @uiw/react-codemirror.
➤ YN0002: │ @apps/hash-frontend@workspace:apps/hash-frontend doesn't provide react-is (pe06c1b), requested by recharts.
➤ YN0002: │ @apps/hash-integration-worker@workspace:apps/hash-integration-worker doesn't provide react (p652198), requested by @blockprotocol/graph.
➤ YN0002: │ @apps/plugin-browser@workspace:apps/plugin-browser doesn't provide webpack-sources (p2d6859), requested by zip-webpack-plugin.
➤ YN0002: │ @blockprotocol/graph@workspace:libs/@blockprotocol/graph [da39f] doesn't provide @types/json-schema (p7740d4), requested by @apidevtools/json-schema-ref-parser.
➤ YN0002: │ @blockprotocol/graph@workspace:libs/@blockprotocol/graph [e419a] doesn't provide @types/json-schema (pa38d4c), requested by @apidevtools/json-schema-ref-parser.
➤ YN0002: │ @blockprotocol/graph@workspace:libs/@blockprotocol/graph doesn't provide @types/json-schema (p15605f), requested by @apidevtools/json-schema-ref-parser.
➤ YN0002: │ @blockprotocol/graph@workspace:libs/@blockprotocol/graph doesn't provide react (p975fc7), requested by @blockprotocol/core.
➤ YN0002: │ @hashintel/block-design-system@workspace:libs/@hashintel/block-design-system [482cc] doesn't provide prop-types (pdc545e), requested by react-type-animation.
➤ YN0002: │ @hashintel/block-design-system@workspace:libs/@hashintel/block-design-system [64938] doesn't provide prop-types (p520cec), requested by react-type-animation.
➤ YN0002: │ @hashintel/block-design-system@workspace:libs/@hashintel/block-design-system doesn't provide prop-types (pdf5207), requested by react-type-animation.
➤ YN0002: │ @hashintel/brunch-agent-transport-aisdk@workspace:libs/@hashintel/brunch-agent/packages/transport-aisdk doesn't provide zod (p91c509), requested by ai.
➤ YN0002: │ @hashintel/ds-components@workspace:libs/@hashintel/ds-components [482cc] doesn't provide esbuild (pdd3db9), requested by esbuild-plugin-svgr and other dependencies.
➤ YN0002: │ @hashintel/ds-components@workspace:libs/@hashintel/ds-components [482cc] doesn't provide playwright (pf22dae), requested by @vitest/browser-playwright.
➤ YN0002: │ @hashintel/ds-components@workspace:libs/@hashintel/ds-components [c2099] doesn't provide esbuild (p62400f), requested by esbuild-plugin-svgr and other dependencies.
➤ YN0002: │ @hashintel/ds-components@workspace:libs/@hashintel/ds-components [c2099] doesn't provide playwright (pe7944e), requested by @vitest/browser-playwright.
➤ YN0002: │ @hashintel/ds-components@workspace:libs/@hashintel/ds-components doesn't provide esbuild (pe4a1b8), requested by esbuild-plugin-svgr and other dependencies.
➤ YN0002: │ @hashintel/ds-components@workspace:libs/@hashintel/ds-components doesn't provide playwright (pe68d39), requested by @vitest/browser-playwright.
➤ YN0002: │ @hashintel/petrinaut@workspace:libs/@hashintel/petrinaut [482cc] doesn't provide zod (p3e879a), requested by ai.
➤ YN0002: │ @hashintel/petrinaut@workspace:libs/@hashintel/petrinaut [95a4e] doesn't provide zod (pe8cf49), requested by ai.
➤ YN0002: │ @hashintel/petrinaut@workspace:libs/@hashintel/petrinaut [c2099] doesn't provide zod (pe7c2dd), requested by ai.
➤ YN0002: │ @hashintel/petrinaut@workspace:libs/@hashintel/petrinaut doesn't provide zod (p3323f1), requested by ai.
➤ YN0002: │ @local/eslint@workspace:libs/@local/eslint doesn't provide eslint-plugin-jsx-a11y (p90ae76), requested by eslint-config-airbnb.
➤ YN0002: │ @local/eslint@workspace:libs/@local/eslint doesn't provide eslint-plugin-react (p47f64a), requested by eslint-config-airbnb.
➤ YN0002: │ @local/eslint@workspace:libs/@local/eslint doesn't provide storybook (p77c4dc), requested by eslint-plugin-storybook.
➤ YN0002: │ @local/harpc-client@workspace:libs/@local/harpc/client/typescript doesn't provide @effect/workflow (p5c866d), requested by @effect/cluster.
➤ YN0002: │ @local/hash-backend-utils@workspace:libs/@local/hash-backend-utils doesn't provide react (pe5f543), requested by @blockprotocol/core and other dependencies.
➤ YN0002: │ @local/hash-graph-sdk@workspace:libs/@local/graph/sdk/typescript doesn't provide react (p5e03d4), requested by @blockprotocol/graph.
➤ YN0002: │ @local/hash-isomorphic-utils@workspace:libs/@local/hash-isomorphic-utils doesn't provide react-dom (p3d46d6), requested by @apollo/client and other dependencies.
➤ YN0002: │ @local/repo-chores@workspace:libs/@local/repo-chores/node doesn't provide react (pe2fb17), requested by @blockprotocol/core.
➤ YN0002: │ @tests/hash-backend-integration@workspace:tests/hash-backend-integration doesn't provide graphql-request (p792347), requested by @graphql-codegen/typescript-graphql-request.
➤ YN0002: │ @tests/hash-backend-integration@workspace:tests/hash-backend-integration doesn't provide graphql-tag (pa67a63), requested by @graphql-codegen/typescript-graphql-request.
➤ YN0002: │ @tests/hash-backend-integration@workspace:tests/hash-backend-integration doesn't provide react (pec02bf), requested by @blockprotocol/graph.
➤ YN0002: │ @tests/hash-playwright@workspace:tests/hash-playwright doesn't provide react (p373b8b), requested by @blockprotocol/graph.
➤ YN0086: │ Some peer dependencies are incorrectly met by your project; run yarn explain peer-requirements <hash> for details, where <hash> is the six-letter p-prefixed code.
➤ YN0086: │ Some peer dependencies are incorrectly met by dependencies; run yarn explain peer-requirements for details.
➤ YN0000: └ Completed
➤ YN0000: ┌ Fetch step
➤ YN0013: │ 3 packages were added to the project (+ 271.35 MiB).
➤ YN0000: └ Completed in 4s 228ms
➤ YN0000: ┌ Link step
➤ YN0073: │ Skipped due to mode=update-lockfile
➤ YN0000: └ Completed
➤ YN0000: ┌ Post-install validation
➤ YN0001: │ Error: Cannot find module '@yarnpkg/types'
Require stack:
- /tmp/renovate/repos/github/hashintel/hash/yarn.config.cjs
- /home/runner/.cache/node/corepack/v1/yarn/4.16.0/yarn.js
    at Module._resolveFilename (node:internal/modules/cjs/loader:1564:15)
    at wrapResolveFilename (node:internal/modules/cjs/loader:1118:27)
    at defaultResolveImplForCJSLoading (node:internal/modules/cjs/loader:1142:10)
    at resolveForCJSWithHooks (node:internal/modules/cjs/loader:1169:12)
    at Module._load (node:internal/modules/cjs/loader:1341:5)
    at wrapModuleLoad (node:internal/modules/cjs/loader:261:19)
    at Module.require (node:internal/modules/cjs/loader:1674:12)
    at require (node:internal/modules/helpers:157:16)
    at Object.<anonymous> (/tmp/renovate/repos/github/hashintel/hash/yarn.config.cjs:7:26)
    at Module._compile (node:internal/modules/cjs/loader:1929:14)
➤ YN0000: └ Completed
➤ YN0000: · Failed with errors in 6s 843ms

@cursor

cursor Bot commented Sep 9, 2026

Copy link
Copy Markdown

PR Summary

Low Risk
Patch-level framework bump with no source changes; main risk is regression from the Next.js runtime upgrade, offset by the security fixes.

Overview
Bumps the pinned Next.js dependency from 15.5.21 to 15.5.24 in @apps/hash-frontend and in @local/hash-isomorphic-utils (devDependency). This is a patch-only dependency update with no application code changes.

The target release includes security fixes for critical RCE issues (Windows-hosted server routing and Image Optimization with AVIF via libheif/sharp), as noted in the Renovate advisory context.

Reviewed by Cursor Bugbot for commit 766ee0b. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions github-actions Bot added area/deps Relates to third-party dependencies (area) area/apps > hash* Affects HASH (a `hash-*` app) area/libs Relates to first-party libraries/crates/packages (area) type/eng > frontend Owned by the @frontend team type/eng > backend Owned by the @backend team area/apps labels Sep 9, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 766ee0b. Configure here.

"material-ui-popup-state": "4.1.0",
"millify": "6.1.0",
"next": "15.5.21",
"next": "15.5.24",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lockfile still pins vulnerable Next.js

High Severity

next is now 15.5.24 in both manifests, but yarn.lock still resolves it to 15.5.21. CI and Vercel run yarn install --immutable, so the install fails, and a non-immutable install from this lockfile would keep the vulnerable release unpatched.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 766ee0b. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/apps > hash* Affects HASH (a `hash-*` app) area/apps area/deps Relates to third-party dependencies (area) area/libs Relates to first-party libraries/crates/packages (area) type/eng > backend Owned by the @backend team type/eng > frontend Owned by the @frontend team

Development

Successfully merging this pull request may close these issues.

1 participant