Skip to content

Fix CVE-2025-66478 by updating Next.js - #9

Open
sc-krishanthakumara wants to merge 2 commits into
Sitecore:mainfrom
sc-krishanthakumara:fix/update-nextjs-cve-2025-66478
Open

Fix CVE-2025-66478 by updating Next.js#9
sc-krishanthakumara wants to merge 2 commits into
Sitecore:mainfrom
sc-krishanthakumara:fix/update-nextjs-cve-2025-66478

Conversation

@sc-krishanthakumara

@sc-krishanthakumara sc-krishanthakumara commented Jan 5, 2026

Copy link
Copy Markdown

Security Fix

Issue

Vercel detected a critical security vulnerability (CVE-2025-66478) in Next.js 15.4.6, blocking production deployments.

Changes

  • Updated Next.js from ^15.4.6 to latest patched version
  • Updated package-lock.json with resolved dependencies

Impact

  • Resolves security vulnerability CVE-2025-66478
  • Unblocks Vercel deployments
  • No breaking changes expected for existing functionality

Testing

  • Build completes successfully
  • Deployment to Vercel succeeds without security errors
  • All existing features work as expected

References

Type of Change

  • Security fix
  • Dependency update

- Update Next.js from 15.4.6 to latest patched version
- Addresses critical security vulnerability blocking Vercel deployments
- Reference: https://vercel.link/CVE-2025-66478
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant