AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Next@16.2.11 Bundles Vulnerable Sharp <0.35.0 (GHSA-F88m-G3jw-G9cj)

Next.js 16.2.11 resolves sharp@0.34.5, which is affected by GHSA-f88m-g3jw-g9cj, causing npm audit to report a vulnerability. Users should upgrade Next.js to a patched version or override sharp to >=0.35.0.

highConfidence 90%Next.jsAffected V16.2.11

Origin Analysis

Next.js 16.2.11 declares sharp ^0.34.x as an optional dependency for image optimization; the resolved version 0.34.5 is below the patched version 0.35.0, matching the advisory.
1. Create package.json with next@16.2.11, react, react-dom. 2. Run npm install. 3. Run npm ls sharp next and npm audit; audit reports GHSA-f88m-g3jw-g9cj for sharp@0.34.5.

Fixing Code Block

Edge Case Audit

Forcing sharp to ^0.35.0 may introduce breaking changes if Next.js 16.2.11 uses APIs removed or altered in sharp 0.35.0; image optimization could fail. Test all image-related functionality. If using Yarn, use the resolutions field instead. Rollback: remove the overrides field and run npm install after upgrading to an official fixed Next.js version.

Ecosystem Topology