[Snyk] Investigation: Next.js Vulnerability - False Positive #8717
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Issue
Snyk Link: SNYK-JS-NEXT-9508709
Issue Type:
Improper AuthorizationPriority: Critical
Summary: Investigated the reported Next.js vulnerability in docs/package.json. Confirmed that Next.js is NOT a dependency of this project. The Snyk alert appears to be a false positive, possibly confusing
next-mdx-remote-clientwithnext.Investigation Details
Findings
nextpackage in direct dependenciesnext-mdx-remote-client(different package)Root Cause
The Snyk webhook payload contained:
next-mdx-remote-clientwithnextEvidence
See SNYK_INVESTIGATION.md for full investigation report.
Additional Context
Snyk Issue Details
{ "vulnerability": { "id": "3ad6663f-f319-4a75-9c25-f27655c49c32", "title": "Improper Authorization", "severity": "critical", "url": "https://security.snyk.io/vuln/SNYK-JS-NEXT-9508709", "description": "Improper Authorization", "cvssScore": 851, "packageName": "NVD", "isUpgradable": true, "isPatchable": false, "fixedIn": [], "upgradePath": [] }, "project": { "id": "fa857427-b8e5-4147-9913-8d56d6835b6d", "name": "continuedev/continue:docs/package.json", "origin": "github", "type": "npm" } }Recommendations
npm audit fixin docs/ to fix actual issues (axios, tar-fs)This agent session was co-authored by peter-parker and Continue.
Summary by cubic
Investigated Snyk alert SNYK-JS-NEXT-9508709 for Next.js in docs/package.json and confirmed it’s a false positive (no Next.js in the dependency tree). Added SNYK_INVESTIGATION.md with evidence and next steps to mark the alert as a false positive and review Snyk configuration.
Written for commit a32c740. Summary will update automatically on new commits.