Skip to content

Security: patch Next.js AVIF image RCE - #15

Merged
Karla Vargas (wearedhundreed) merged 11 commits into
mainfrom
security/next-avif-rce-ghsa-2xp9
Sep 14, 2026
Merged

Karla Vargas (wearedhundreed) merged 11 commits into
mainfrom
security/next-avif-rce-ghsa-2xp9

Conversation

@wearedhundreed

Copy link
Copy Markdown
Member

Security fix

Updates Next.js from 13.3.4 to patched version 15.5.24 in both affected Speedometer news-next fixtures:

  • Speedometer3.0/resources/newssite/news-next
  • Speedometer3.1/resources/newssite/news-next

Regenerates both lockfiles and retains the existing direct uuid 9.x dependency to avoid bundling unrelated major-version changes.

Fixes GitHub advisory GHSA-2xp9-vwfh-vxw4.

Existing mitigation

Both fixtures use static export with images.unoptimized: true, so the vulnerable server-side optimizer is not expected to be active. The dependency upgrade removes the vulnerable Next.js release from the lockfiles.

Validation requested

  • Install with the repository-supported Node/npm versions
  • Build both news-next fixtures
  • Run repository CI and benchmark smoke tests

Do not merge if either fixture fails to build.

Copy link
Copy Markdown
Member Author

CI workflow added and validated.

✅ Speedometer 3.0 news-next: install, patched-version check, and static production build passed
✅ Speedometer 3.1 news-next: install, patched-version check, and static production build passed
✅ Least-privilege contents: read; no secrets or deployment permissions
✅ Sparse checkout limits runner access and checkout time

Successful run: https://github.com/wearedhundreed/WebKit/actions/runs/34842168608

@wearedhundreed
Karla Vargas (wearedhundreed) merged commit 54cf7b8 into main Sep 14, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant