🔒 Critical security fix: remote code execution in poll preview images
This patch fixes a critical vulnerability in an upstream dependency. Please upgrade as soon as possible.
Rallly v4.8.0 through v4.15.3 ship a version of Next.js affected by GHSA-vcvr-r3jv-pc5j (critical, CVSS 9.5). The ImageResponse renderer from next/og can be made to execute code on the server when attacker-controlled text reaches the image it renders.
Rallly uses that renderer for poll link previews at /api/og-image-poll, and the poll title and author come straight from the query string. That endpoint needs no sign-in, so anyone who can reach your instance can send a crafted request.
This release upgrades Next.js from 16.3.3 to 16.3.8, which contains the fix. Nothing else changes.
If you can't upgrade right away, block /api/og-image-poll at your reverse proxy until you can. Shared poll links will show no preview image in the meantime; nothing else is affected.
What's Changed
- 🔒️ Upgrade Next.js to 16.3.8 to patch next/og RCE (#3451)
Full Changelog: v4.15.3...v4.15.4