') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); chore(nextjs): Update next to patched versions for GHSA-26hh-7cqf-hhc6 by jacekradko · Pull Request #8547 · clerk/javascript · GitHub
Skip to content

chore(nextjs): Update next to patched versions for GHSA-26hh-7cqf-hhc6 - #8547

Merged
jacekradko merged 4 commits into
mainfrom
jacek/next-security-bump-15.5.18
May 14, 2026
Merged

chore(nextjs): Update next to patched versions for GHSA-26hh-7cqf-hhc6#8547
jacekradko merged 4 commits into
mainfrom
jacek/next-security-bump-15.5.18

Conversation

@jacekradko

Copy link
Copy Markdown
Contributor

Bumps next to 15.5.18 to pick up the fix for GHSA-26hh-7cqf-hhc6, a high-severity (CVSS 7.5) Middleware/Proxy bypass in App Router applications via segment-prefetch routes (incomplete-fix follow-up). Mirrors #8281: updates the @clerk/nextjs devDep, the Next.js integration templates, the @clerk/msw peer floor, and the pnpm-workspace.yaml minimum-release-age exclusion. Peer range left as-is; users on the App Router should upgrade to 15.5.18 or later.

Bump `next` to `15.5.18` to pick up the fix for GHSA-26hh-7cqf-hhc6,
a high-severity (CVSS 7.5) Middleware/Proxy bypass in App Router
applications via segment-prefetch routes.
@changeset-bot

changeset-botBot commented May 14, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: ac5aac4

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
NameType
@clerk/nextjsPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 14, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 14, 2026 7:00pm

Request Review

@coderabbitai

coderabbitaiBot commented May 14, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 8f8e413d-4675-47e6-a16b-ac84a885cb91

📥 Commits

Reviewing files that changed from the base of the PR and between f684acb and ac5aac4.

📒 Files selected for processing (2)
  • packages/msw/package.json
  • packages/nextjs/package.json
✅ Files skipped from review due to trivial changes (1)
  • packages/nextjs/package.json
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/msw/package.json

📝 Walkthrough

Walkthrough

This pull request adds a changeset for a Next.js security fix (GHSA-26hh-7cqf-hhc6), bumps Next.js in multiple integration templates (including a 16.2.6 bump for cache-components), tightens package constraints (packages/msw peerDependency and packages/nextjs devDependency), and updates pnpm-workspace.yaml's excluded Next.js entry to 15.5.18.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title accurately summarizes the main change: updating Next.js to patched versions (15.5.18 and 16.2.6) to address the GHSA-26hh-7cqf-hhc6 security vulnerability.
Description check✅ PassedThe description is directly related to the changeset, detailing the security fix and all updated components including devDependencies, templates, peer floors, and workspace configuration.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented May 14, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8547

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8547

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8547

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8547

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8547

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8547

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8547

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8547

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8547

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8547

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8547

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8547

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8547

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8547

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8547

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8547

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8547

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8547

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8547

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8547

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8547

commit: ac5aac4

The next-cache-components template floor at ^16.2.3 still permitted
versions affected by GHSA-26hh-7cqf-hhc6 (16.0.0–16.2.5). Raise it
to ^16.2.6 and tighten the changeset wording to call out the 16.x
patched line.
@jacekradko
jacekradko merged commit 54ddc2f into mainMay 14, 2026
43 checks passed
@jacekradko
jacekradko deleted the jacek/next-security-bump-15.5.18 branch May 14, 2026 19:20
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano