Skip to content

[SECURITY] Critical Next.js vulnerability in transitive dependency #84

@Shooksie

Description

@Shooksie

Summary

npm audit reports 1 critical severity vulnerability in Next.js v14.2.21 (transitive dependency).

Details

  • Severity: Critical
  • Package: next (transitive dependency)
  • Version: v14.2.21

Recommended Fix

Run npm audit fix --force to patch the vulnerable dependency, then verify build still passes.

Context

Identified in quality audit on 2026-03-19 after 28 PRs merged in 7 days.

Metadata

Metadata

Assignees

No one assigned

    Labels

    P0-criticalCritical priority - immediate action requiredsecuritySecurity issue

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions