Skip to content

⚠ - Bump Next.js version to prevent CVE-2025-55182 #305

@Jaimayal

Description

@Jaimayal

I noticed that useSend is currently running a vulnerable Next.js version (see https://www.cve.org/CVERecord?id=CVE-2025-55182). This vulnerability allows remote code execution, so all instances running useSend are affected right now.

Since useSend itself relies on a public callback endpoint exposed on a valid domain in order to collect email sending stats, it would be great if you could bump Next.js to a patched version as soon as possible.

References:
https://nextjs.org/blog/CVE-2025-66478
GHSA-9qr9-h5gf-34mp

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions