Skip to content

fix: upgrade next to 13.5.9, 14.2.25, 15.2.3, 12.3.5 (CVE-2025-29927)#10250

Open
orbisai0security wants to merge 1 commit intoshadcn-ui:mainfrom
orbisai0security:fix-cve-2025-29927-next
Open

fix: upgrade next to 13.5.9, 14.2.25, 15.2.3, 12.3.5 (CVE-2025-29927)#10250
orbisai0security wants to merge 1 commit intoshadcn-ui:mainfrom
orbisai0security:fix-cve-2025-29927-next

Conversation

@orbisai0security
Copy link
Copy Markdown

Summary

Upgrade next from 13.4.19 to 13.5.9, 14.2.25, 15.2.3, 12.3.5 to fix CVE-2025-29927.

Vulnerability

Field Value
ID CVE-2025-29927
Severity CRITICAL
Scanner trivy
Rule CVE-2025-29927
File packages/shadcn/test/fixtures/frameworks/next-app-src/pnpm-lock.yaml

Description: nextjs: Authorization Bypass in Next.js Middleware

Changes

  • packages/shadcn/test/fixtures/frameworks/next-app-src/package.json
  • packages/shadcn/test/fixtures/frameworks/next-app-src/pnpm-lock.yaml

Verification

  • Build passes
  • Scanner re-scan confirms fix
  • Code review passed

Automated security fix by OrbisAI Security

@vercel
Copy link
Copy Markdown
Contributor

vercel bot commented Apr 1, 2026

@orbisai0security is attempting to deploy a commit to the shadcn-pro Team on Vercel.

A member of the Team first needs to authorize it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant