Only finding is a version string mismatch inside a vendored copy of @babel/runtime (common in Next.js's dist/compiled tree). No malicious code, exfiltration, or suspicious behavior present in the supplied sources.
AI breakdown
Plain-English summary of what this package does and how it behaves.
next is the core npm package for the Next.js React framework, providing a CLI binary and server entrypoint for building and running React applications.
Capabilities
- Exposes 'next' CLI binary
- Includes dev, build, and release scripts using taskr and turbo
- Depends on compilation helpers and postcss
Data access
- None observed
Network
- No network access observed
Standard framework package with build tooling; one static finding notes a version metadata mismatch that may warrant verification before install.
Dependency & execution chain
Every package this one pulls in, colored by verdict. Expand to walk the tree.
Security findings (1)
Static analysis rule matches, with the exact code that triggered them.
Version mismatch in dist/compiled/@babel/runtime/package.json
Known vulnerabilities (23)
Published CVEs / advisories affecting this version.
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
Next.js: Server-Side Request Forgery in Server Actions on custom servers
Next.js Vulnerable to Denial of Service with Server Components
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
Next.js: Denial of Service in App Router using Server Actions
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Next.js has a Denial of Service with Server Components
Next.js: Unbounded next/image disk cache growth can exhaust storage
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Next.js: Unbounded Server Action payload in Edge runtime
Next.js: Cache confusion of response bodies for requests with bodies
Next.js: Unauthenticated disclosure of internal Server Function endpoints
Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
Next.js: HTTP request smuggling in rewrites
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
Next.js has a Denial of Service in the Image Optimization API
Next.js vulnerable to cache poisoning in React Server Component responses
Next.js's Middleware / Proxy redirects can be cache-poisoned
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
Files in package (500)
How ShadowCanopy checks npm packages
ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.
This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/npm/next