mirror of
https://github.com/supermemoryai/supermemory.git
synced 2026-09-30 01:51:28 +00:00
GHSA-p293-qw3h-jr36 (CVE-2026-75604, critical): unauthenticated RCE on Windows-hosted Next.js servers. apps/web was on ^16.0.11 (affected: >=16.0 <16.3.3). bun.lock regenerated (resolves next 16.3.4). Follows up #1655, which covered chatapp, sdk-playground and memory-graph-playground but missed web. |
||
|---|---|---|
| .. | ||
| app | ||
| public | ||
| .env.example | ||
| .gitignore | ||
| biome.json | ||
| console-origin.ts | ||
| middleware.ts | ||
| next.config.ts | ||
| open-next.config.ts | ||
| package.json | ||
| README.md | ||
| tsconfig.json | ||
| wrangler.jsonc | ||
@repo/web
Serves app.supermemory.ai. Every request is forwarded to the console: plugin and OAuth paths get an immediate redirect with the query string intact, and everything else shows a short notice before moving on.
Set NEXT_PUBLIC_CONSOLE_URL to point at a different console origin during local development.