Repository navigation
[HIGH] fix: CVE-2026-23869 — bump next - #148
Open
Pattern Security Automation (pattern-security-automation) wants to merge 1 commit into
Open
Pattern Security Automation (pattern-security-automation) wants to merge 1 commit into
Pattern Security Automation (pattern-security-automation) wants to merge 1 commit into
Conversation
CVE: CVE-2026-23869 Component: next Fixed version: 16.3.6 Manifest: web/package.json Dependency type: direct
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The framework upgrade refreshes native transitive dependencies, so successful CI and application-build validation should be confirmed by a human.
Review effort: Balanced
Findings: None
What changed in this PR
Updates Next.js beyond the version affected by CVE-2026-23869.
Changes:
- Raises the Next.js dependency minimum to 16.3.6.
- Regenerates the lockfile, resolving Next.js 16.3.8 and updated transitive dependencies.
| File | Description |
|---|---|
web/package.json |
Updates the Next.js dependency range. |
web/pnpm-lock.yaml |
Locks the updated Next.js dependency graph. |
Files not reviewed (1)
- web/pnpm-lock.yaml: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Supply Chain Vulnerability — Auto-Remediation PR
CVE Details
CVE-2026-23869patterninc/heimdallnext16.2.3^16.1.6What Changed
next:
^16.1.6→16.3.6web/package.jsonweb/pnpm-lock.yamlLock File Status
Lock file updated
CI Validation
False positive?
AI Triage Analysis
Verdict: Needs Review
Reasoning: The 'next' package is a direct dependency listed in web/package.json at version '^16.1.6', which is below the fixed version 16.2.3. The Next.js framework is actively used throughout the codebase - source files import from 'next/dynamic', 'next/link', 'next/image', and 'next/navigation', indicating the package is genuinely in use, not just listed. However, the specific vulnerable functionality in this CVE (CVE-2026-23869) cannot be confirmed as reachable without knowing exactly which Next.js feature or code path is affected, as only 15 of 157 source files were sampled. Given the version constraint allows installation of a vulnerable version and the package is clearly used, this warrants further review to confirm the specific vulnerable code path is exercised.
References
Developer feedback
Was this automation helpful? Share feedback (takes ~1 min)
Auto-generated by Pattern Security Automation