针对以下问题的极简复现:Next.js 16.2.4 内置了 picomatch 4.0.3,位于 node_modules/next/dist/compiled/picomatch/,该版本受 CVE-2026-33671(高危)影响。npm 的 overrides 无法触及捆绑副本。
npm install
cat node_modules/next/dist/compiled/picomatch/package.json
# → {"name":"picomatch","main":"index.js",...} (版本字段已被移除)
npx next build
docker build -t next-picomatch-repro .
trivy image next-picomatch-repro
预期输出:
picomatch (package.json) | CVE-2026-33671 | HIGH | fixed | 4.0.3 | 4.0.4
overrides 无效package.json 可以扩展为:
"overrides": {
"picomatch": "4.0.4"
}
这会正确安装 node_modules/[email protected],但 node_modules/next/dist/compiled/picomatch/ 仍停留在 4.0.3,因为它被捆绑在 Next.js 自身的 tarball 中。
Next.js 发布一个补丁版本,将 dist/compiled/picomatch/ 从 picomatch ≥ 4.0.4 重新捆绑。下游使用者随后通过常规的 npm install 即可获取修复。