npm package intelligence

next — deep security report

ShadowCanopy's full breakdown of next on npm: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Safe to use
Deep-scanned by ShadowCanopy — no threats found in its code, dependencies, or network behavior.
Scanned 9/20/2026
Approvednext@14.2.35View on registry ↗latest: 14.2.35

Only finding is a version string mismatch inside a vendored copy of @babel/runtime (common in Next.js's dist/compiled tree). No malicious code, exfiltration, or suspicious behavior present in the supplied sources.

Protect your projects free

AI breakdown

Plain-English summary of what this package does and how it behaves.

next is the core npm package for the Next.js React framework, providing a CLI binary and server entrypoint for building and running React applications.

Capabilities

  • Exposes 'next' CLI binary
  • Includes dev, build, and release scripts using taskr and turbo
  • Depends on compilation helpers and postcss

Data access

  • None observed

Network

  • No network access observed

Standard framework package with build tooling; one static finding notes a version metadata mismatch that may warrant verification before install.

Dependency & execution chain

Every package this one pulls in, colored by verdict. Expand to walk the tree.

12 packages7 direct
next@14.2.351 finding
postcss@8.5.282 findings
@next/env@16.3.52 findings
styled-jsx@5.1.72 findings
@swc/helpers@0.5.23
caniuse-lite@1.0.30001810

Security findings (1)

Static analysis rule matches, with the exact code that triggered them.

mediumVersion metadata mismatchATK-007dist/compiled/@babel/runtime/package.json

Version mismatch in dist/compiled/@babel/runtime/package.json

Known vulnerabilities (23)

Published CVEs / advisories affecting this version.

GHSA-2xp9-vwfh-vxw4CRITICAL

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

GHSA-p293-qw3h-jr36CRITICAL

Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

GHSA-36qx-fr4f-26g5HIGH

Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n

GHSA-89xv-2m56-2m9xHIGH

Next.js: Server-Side Request Forgery in Server Actions on custom servers

GHSA-8h8q-6873-q5fjHIGH

Next.js Vulnerable to Denial of Service with Server Components

GHSA-c4j6-fc7j-m34rHIGH

Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades

GHSA-h25m-26qc-wcjfHIGH

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

GHSA-m99w-x7hq-7vfjHIGH

Next.js: Denial of Service in App Router using Server Actions

GHSA-p9j2-gv94-2wf4HIGH

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

GHSA-q4gf-8mx6-v5v3HIGH

Next.js has a Denial of Service with Server Components

GHSA-3x4c-7xq6-9pq8MODERATE

Next.js: Unbounded next/image disk cache growth can exhaust storage

GHSA-4633-3j49-mh5qMODERATE

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

GHSA-4c39-4ccg-62r3MODERATE

Next.js: Unbounded Server Action payload in Edge runtime

GHSA-68g3-v927-f742MODERATE

Next.js: Cache confusion of response bodies for requests with bodies

GHSA-955p-x3mx-jcvpMODERATE

Next.js: Unauthenticated disclosure of internal Server Function endpoints

GHSA-9g9p-9gw9-jx7fMODERATE

Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

GHSA-ffhc-5mcf-pf4qMODERATE

Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces

GHSA-ggv3-7p47-pfv8MODERATE

Next.js: HTTP request smuggling in rewrites

GHSA-gx5p-jg67-6x7hMODERATE

Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

GHSA-h64f-5h5j-jqjhMODERATE

Next.js has a Denial of Service in the Image Optimization API

GHSA-wfc6-r584-vfw7MODERATE

Next.js vulnerable to cache poisoning in React Server Component responses

GHSA-3g8h-86w9-wvmqLOW

Next.js's Middleware / Proxy redirects can be cache-poisoned

GHSA-vfv6-92ff-j949LOW

Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

Package metadata

LicenseMIT

The React Framework

Homepage ↗Repository ↗

Files in package (500)

dist/compiled/@babel/runtime/LICENSEpackage/dist/compiled/@babel/runtime/LICENSEdist/compiled/@mswjs/interceptors/ClientRequest/LICENSEpackage/dist/compiled/@mswjs/interceptors/ClientRequest/LICENSEdist/compiled/@napi-rs/triples/LICENSEpackage/dist/compiled/@napi-rs/triples/LICENSEdist/compiled/@opentelemetry/api/LICENSEpackage/dist/compiled/@opentelemetry/api/LICENSEdist/compiled/@vercel/nft/LICENSEpackage/dist/compiled/@vercel/nft/LICENSEdist/compiled/@vercel/og/LICENSEpackage/dist/compiled/@vercel/og/LICENSEdist/compiled/@vercel/og/satori/LICENSEpackage/dist/compiled/@vercel/og/satori/LICENSEdist/compiled/acorn/LICENSEpackage/dist/compiled/acorn/LICENSEdist/compiled/anser/LICENSEpackage/dist/compiled/anser/LICENSEdist/compiled/assert/LICENSEpackage/dist/compiled/assert/LICENSEdist/compiled/babel/LICENSEpackage/dist/compiled/babel/LICENSEdist/compiled/browserify-zlib/LICENSEpackage/dist/compiled/browserify-zlib/LICENSEdist/compiled/browserslist/LICENSEpackage/dist/compiled/browserslist/LICENSEdist/compiled/buffer/LICENSEpackage/dist/compiled/buffer/LICENSEdist/compiled/bytes/LICENSEpackage/dist/compiled/bytes/LICENSEdist/compiled/ci-info/LICENSEpackage/dist/compiled/ci-info/LICENSEdist/compiled/cli-select/LICENSEpackage/dist/compiled/cli-select/LICENSEdist/compiled/commander/LICENSEpackage/dist/compiled/commander/LICENSEdist/compiled/comment-json/LICENSEpackage/dist/compiled/comment-json/LICENSEdist/compiled/compression/LICENSEpackage/dist/compiled/compression/LICENSE

How ShadowCanopy checks npm packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/npm/next