"We did a number of refactors [...] This also fixes a critical security vulnerability." ๐Ÿ‘€

CVE-2025-55182, an RCE in React Server Components just landed:

react.dev/blog/2025/12/03/crit

Enjoy your patching, and make sure to check your bundled frameworks and dependencies.

Here's the commit:
github.com/facebook/react/comm

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mstdn.social/users/jschauma/statuses/115656448649390437 on your instance and quote it. (Note that quoting is not supported in Mastodon.)