Skip to content

Fix React Server Components CVE vulnerabilities in remaining templates#707

Merged
sragss merged 2 commits into
masterfrom
fix/remaining-cve-templates
Jan 13, 2026
Merged

Fix React Server Components CVE vulnerabilities in remaining templates#707
sragss merged 2 commits into
masterfrom
fix/remaining-cve-templates

Conversation

@sragss

@sragss sragss commented Jan 13, 2026

Copy link
Copy Markdown
Contributor

Summary

Updates Next.js from 15.4.10 to 15.5.4 in remaining vulnerable templates:

  • templates/assistant-ui
  • templates/next-image
  • templates/next-video-template

CVEs Addressed

Test plan

  • Verify Vercel deployments succeed
  • Test template functionality

🤖 Generated with Claude Code

Updates Next.js from 15.4.10 to 15.5.4 in:
- templates/assistant-ui
- templates/next-image
- templates/next-video-template

Addresses:
- CVE-2025-55182: Node.js-only React Server Components RCE
- CVE-2025-55183: Potential Authorization Bypass for RSC Actions
- CVE-2025-55184: Potential Authorization Bypass for Server Function

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jan 13, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
assistant-ui-template Ready Ready Preview, Comment Jan 13, 2026 5:17pm
component-registry Ready Ready Preview, Comment Jan 13, 2026 5:17pm
echo-control Ready Ready Preview, Comment Jan 13, 2026 5:17pm
echo-next-boilerplate Ready Ready Preview, Comment Jan 13, 2026 5:17pm
echo-next-image Ready Ready Preview, Comment Jan 13, 2026 5:17pm
echo-next-sdk-example Ready Ready Preview, Comment Jan 13, 2026 5:17pm
echo-video-template Ready Ready Preview, Comment Jan 13, 2026 5:17pm
echo-vite-sdk-example Ready Ready Preview, Comment Jan 13, 2026 5:17pm
next-chat-template Ready Ready Preview, Comment Jan 13, 2026 5:17pm
react-boilerplate Ready Ready Preview, Comment Jan 13, 2026 5:17pm
react-chat Ready Ready Preview, Comment Jan 13, 2026 5:17pm
react-image Ready Ready Preview, Comment Jan 13, 2026 5:17pm

@railway-app

railway-app Bot commented Jan 13, 2026

Copy link
Copy Markdown

🚅 Deployed to the echo-pr-707 environment in echo

Service Status Web Updated (UTC)
echo 🕒 Building (View Logs) Web Jan 13, 2026 at 5:14 pm

- Updates Next.js from 15.5.4 to 15.5.9 to address CVE-2025-66478
- Adds openai dependency to assistant-ui template (required by echo-react-sdk)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant