Skip to content

[Aikido] Fix security issue in next#2

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-33758295-5kck
Open

[Aikido] Fix security issue in next#2
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-33758295-5kck

Conversation

@aikido-autofix
Copy link
Copy Markdown

Upgrade Next.js to fix middleware code injection vulnerability in Turbopack that could allow arbitrary code execution.

⚠️ Breaking changes analysis not available for: next

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-45109
HIGH
[next] Incomplete fix for code injection vulnerability in middleware.ts when using Turbopack, allowing potential remote code execution through unvalidated input processing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants