AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Next.Js 15.5.23 Bundles Vulnerable Postcss And Sharp Dependencies

Running `npm audit` on a project created with Next.js 15.5.23 reports high severity vulnerabilities from transitive dependencies `postcss` and `sharp`. The Next.js package pins outdated versions of these packages, requiring a dependency bump to secure patch releases.

highConfidence 90%Next.jsAffected V15.5.23

Origin Analysis

Next.js 15.5.23's `packages/next/package.json` declares `postcss` and `sharp` with versions older than the patched releases (`postcss` < 8.5.23 and `sharp` < 0.34.0). These older versions contain known security vulnerabilities (e.g., GHSA-r28c-9q8g-f849), and Next.js does not override these transitive dependencies to secure versions.
1. Run `npx create-next-app@15.5.23 my-audit-test --typescript --eslint --no-tailwind --src-dir --app --import-alias "@/*"` 2. Navigate into the directory: `cd my-audit-test` 3. Run `npm audit` 4. Observe high severity vulnerabilities reported for `postcss` and `sharp`.

Fixing Code Block

Edge Case Audit

Upgrading `sharp` across major/minor lines (0.33 -> 0.34/0.35) may introduce breaking changes in image processing APIs or platform-specific binary incompatibilities (e.g., older Linux distributions with older glibc, or Windows/macOS edge cases). PostCSS 8.5.23 is a patch-level change and is generally backward compatible, but some third-party PostCSS plugins may still rely on older behavior. Test `next build` and image optimization on all supported Node versions and platforms before shipping. Rollback: revert `packages/next/package.json` and lockfile changes, then run `npm install` to restore previous dependency versions.

Ecosystem Topology