Skip to content

[HIGH] fix: CVE-2026-23869 — bump next - #148

Open
Pattern Security Automation (pattern-security-automation) wants to merge 1 commit into
mainfrom
wiz-fix-cve-2026-23869-01edd3aa
Open

Pattern Security Automation (pattern-security-automation) wants to merge 1 commit into
mainfrom
wiz-fix-cve-2026-23869-01edd3aa

Conversation

@pattern-security-automation

Supply Chain Vulnerability — Auto-Remediation PR

This PR was automatically generated by Pattern Security Automation.
Please review the dependency change and ensure CI passes before merging.


CVE Details

Field Value
CVE CVE-2026-23869
Severity HIGH
Repository patterninc/heimdall
Vulnerable package next
Fixed version 16.2.3
Dependency type Direct
Previous version ^16.1.6
Language javascript

What Changed

next: ^16.1.6 → 16.3.6

  • web/package.json
  • web/pnpm-lock.yaml

Lock File Status

Lock file updated

CI Validation

This PR relies on the repository's existing CI pipeline to validate that the
dependency update does not break tests. Please ensure all checks pass before merging.

False positive?

If you've reviewed this and the CVE is not actually exploitable here, add the
wiz-false-positive label to this PR before closing it. The auto-remediation
pipeline will record the false positive, stop re-flagging this CVE, and (if enabled)
mark it rejected in Wiz.

AI Triage Analysis

Verdict: Needs Review

Reasoning: The 'next' package is a direct dependency listed in web/package.json at version '^16.1.6', which is below the fixed version 16.2.3. The Next.js framework is actively used throughout the codebase - source files import from 'next/dynamic', 'next/link', 'next/image', and 'next/navigation', indicating the package is genuinely in use, not just listed. However, the specific vulnerable functionality in this CVE (CVE-2026-23869) cannot be confirmed as reachable without knowing exactly which Next.js feature or code path is affected, as only 15 of 157 source files were sampled. Given the version constraint allows installation of a vulnerable version and the package is clearly used, this warrants further review to confirm the specific vulnerable code path is exercised.

References

Developer feedback

Was this automation helpful? Share feedback (takes ~1 min)


Auto-generated by Pattern Security Automation

CVE: CVE-2026-23869
Component: next
Fixed version: 16.3.6
Manifest: web/package.json
Dependency type: direct

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The framework upgrade refreshes native transitive dependencies, so successful CI and application-build validation should be confirmed by a human.

Review effort: Balanced
Findings: None

What changed in this PR

Updates Next.js beyond the version affected by CVE-2026-23869.

Changes:

  • Raises the Next.js dependency minimum to 16.3.6.
  • Regenerates the lockfile, resolving Next.js 16.3.8 and updated transitive dependencies.
File Description
web/​package.json Updates the Next.js dependency range.
web/​pnpm-lock.yaml Locks the updated Next.js dependency graph.
Files not reviewed (1)
  • web/pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants