Skip to content

Conversation

@CruzMolina
Copy link
Member

@CruzMolina CruzMolina commented Dec 11, 2025

Address critical security vulnerabilities disclosed 2025-12-11:

Updated packages:

  • next: 15.4.8 → 15.5.8
  • eslint-config-next: 15.4.8 → 15.5.8

Note

Upgrades Next.js and its ESLint config to 15.5.8 and refreshes lockfile with corresponding transitive updates.

  • Dependencies:
    • Upgrade next from 15.4.815.5.8.
  • Dev Tooling:
    • Upgrade eslint-config-next from 15.4.815.5.8.
  • Lockfile:
    • Update pnpm-lock.yaml to reflect new next version and related packages (@next/* swc binaries, next-seo, next-sitemap, nextra, nextra-theme-docs).

Written by Cursor Bugbot for commit 2a89707. This will update automatically on new commits. Configure here.

Address critical security vulnerabilities disclosed 2025-12-11:
- CVE-2025-55184 (High): DoS via infinite loop in App Router
- CVE-2025-55183 (Medium): Source code exposure of Server Functions

Updated packages:
- next: 15.4.8 → 15.5.8
- eslint-config-next: 15.4.8 → 15.5.8
@CruzMolina CruzMolina requested a review from a team as a code owner December 11, 2025 23:23
@CruzMolina CruzMolina enabled auto-merge (squash) December 11, 2025 23:23
@CruzMolina CruzMolina merged commit 04440d2 into main Dec 11, 2025
19 checks passed
@CruzMolina CruzMolina deleted the build/CVE-2025-55184-CVE-2025-55183 branch December 11, 2025 23:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants