Skip to content

fix: upgrade Next.js to 14.2.34 (CVE-2025-55182)#20

Open
markimbriaco wants to merge 1 commit intoctate:mainfrom
markimbriaco:fix/upgrade-nextjs-cve-2025-55182
Open

fix: upgrade Next.js to 14.2.34 (CVE-2025-55182)#20
markimbriaco wants to merge 1 commit intoctate:mainfrom
markimbriaco:fix/upgrade-nextjs-cve-2025-55182

Conversation

@markimbriaco
Copy link
Copy Markdown

Summary

Upgrades Next.js from 13.4.19 to 14.2.34 to address CVE-2025-55182, a React Server Components RCE vulnerability.

Changes

  • : 13.4.19 → 14.2.34
  • : 13.4.19 → 14.2.34

Testing

  • Build completes successfully
  • No breaking changes detected
  • Static generation working correctly

Security Impact

This upgrade fixes a critical remote code execution vulnerability in React Server Components. See CVE-2025-55182 for details.

Closes #19

Upgrades Next.js from 13.4.19 to 14.2.34 to address CVE-2025-55182,
a React Server Components RCE vulnerability.

Also upgrades eslint-config-next to match the Next.js version.

Build tested successfully with no breaking changes.

Closes ctate#19
@markimbriaco
Copy link
Copy Markdown
Author

Hey Chris! Noticed the CVE issue sitting open so I went ahead and bumped Next.js to 14.2.34 (and eslint-config-next to match). Ran a full build to confirm everything works — no breaking changes detected.

The upgrade addresses CVE-2025-55182, the React Server Components RCE vulnerability. Build output looks clean and static generation is working correctly.

Let me know if you'd like any adjustments!

@markimbriaco · @PreviewOps

@markimbriaco
Copy link
Copy Markdown
Author

@ctate

@vercel
Copy link
Copy Markdown

vercel bot commented Apr 9, 2026

@markimbriaco is attempting to deploy a commit to the ACS Team on Vercel.

A member of the Team first needs to authorize it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant