vercel/next.js · error · Error
No safe Next.js update is currently available.
Error message
No safe Next.js update is currently available.
What it means
When the installed Next.js version is inside a known vulnerable range, selectSecurityTarget searches the latest stable release of each major (>= the installed major) for one that is newer than the installed version AND outside all vulnerable ranges. This error is thrown when no such release exists — every newer candidate release is itself affected by an open advisory, so the tool refuses to pick an unsafe target.
Solutions
- Wait for the patched Next.js release and re-run `next upgrade`; the tool will then select it automatically.
- Check the referenced advisory feeds (the error context lists ADVISORIES/NPM_ADVISORIES URLs) for the fixed version and manually install it with npm/pnpm.
- If you believe the advisory does not affect your usage, upgrade manually with an explicit version while consciously accepting the flagged risk.
- Upgrade to the newest available major anyway only if you have independently verified the vulnerability does not apply (not recommended for production).
Example fix
// before npx next upgrade // error: No safe Next.js update is currently available. // after: wait for / manually pin the patched release npm install next@<patched-version>
Defensive patterns
Strategy: fallback
Validate before calling
// pre-check whether the installed version is currently flagged
const advisories = await (await fetch('https://api.github.com/advisories?ecosystem=npm&affects=next')).json()
const affected = advisories.some(a => a.vulnerabilities.some(v =>
require('semver').satisfies(require('next/package.json').version, v.vulnerable_version_range)))
console.log(affected ? 'Affected: wait for patched release' : 'Not affected: normal upgrade path') Try / catch
try {
await upgrade()
} catch (e) {
if (e.message === 'No safe Next.js update is currently available.') {
// do NOT force-upgrade; wait for the patched release or review the advisory manually
} else throw e
} Prevention
- Don't upgrade the moment a new Next.js version ships during an active security incident; check advisories first.
- Subscribe to Next.js security advisories to know when the patched release lands.
- Avoid canary/RC versions in production to stay inside well-covered safe ranges.
When it happens
Trigger: Running `next upgrade` (security path via `selected`) while the installed version matches a vulnerable range and every newer latest-stable major release also satisfies some vulnerable range — e.g. installing a freshly-published, already-advisory-affected release, or an advisory that spans all current majors.
Common situations: A zero-day advisory covering the latest Next.js releases; upgrading immediately after a new vulnerable version shipped before a patched release is out; pinning to canary/RC versions that all fall in affected ranges.
Related errors
- Next.js is affected by an active advisory.
- Could not check Next.js security advisories. Continuing…
- Could not determine the installed Next.js version.
- The running Next.js version is not valid semver.
- AI upgrades are not available for prerelease versions of…
AI-assisted analysis of vercel/next.js@34433fd12e (2026-09-20).
Data as JSON: /api/errors/162bc8667578226e.
Report an issue: GitHub.
Appendix: source
Thrown at packages/next/src/lib/upgrade/prepare-upgrade.ts:549
}
}
for (const major of [...latest.keys()].sort((a, b) => a - b)) {
if (major < semver.major(source)) {
continue
}
const candidate = latest.get(major)!
if (
semver.gt(candidate.version, source) &&
!ranges.some((range) => semver.satisfies(candidate.version, range))
) {
return candidate
}
}
throw new Error('No safe Next.js update is currently available.')
}
View on GitHub (pinned to 34433fd12e)