react

Back Open Paginator
03.12.2025 20:11
msw (@msw@mstdn.social)

A public service announcement regarding CVEs: one identified vulnerability gets one #CVE.

Each vendor doesn't get their own CVE that corresponds to their security bulletin.

CVE-2025-66478 is REJECTED as duplicate of CVE-2025-55182

#CVE_2025_66478 #CVE_2025_55182 #React #RCE #InfoSec

cve.org/CVERecord?id=CVE-2025-




Show Original Post


03.12.2025 20:09
minus (@minus@nanao.cybtex.fr)

Unauthenticated Remote Code Execution vulnerability in React Server Components #vuln #reactreact.dev/blog/2025/12/03/crit ] #informatique




Show Original Post


03.12.2025 19:47
post (@post@mander.xyz)

Critical Security Vulnerability in React Server Components

mander.xyz/post/42962066




Show Original Post


03.12.2025 19:35
ngate (@ngate@mastodon.social)

😱 Oh no, another RCE vulnerability! Quick, run around in circles and panic about and Next.js being the end of the world. 😜 Don't worry, GitHub's magical AI Copilot will save the day by writing "better" code while you wish for a time machine to undo your poor framework choices. 🔧🛠️
github.com/vercel/next.js/secu




Show Original Post


03.12.2025 19:29
sir_pepe (@sir_pepe@mastodon.social)

Critical Security Vulnerability in Server Components 🍿

react.dev/blog/2025/12/03/crit




Show Original Post


03.12.2025 19:17
h4ckernews (@h4ckernews@mastodon.social)

RCE Vulnerability in React and Next.js

github.com/vercel/next.js/secu

.js




Show Original Post


03.12.2025 18:58
kiwi (@kiwi@defcon.social)

New 10.0 CVSS vuln in react, specifically RCE in react server endpoints.

Seems to be affecting #react versions 19-19.2, discovered by lachlan.nz/blog, which is also where I assume we'll see their writeup!

Might post one later, we'll see.




Show Original Post


03.12.2025 18:35
ngate (@ngate@mastodon.social)

Breaking news: 🚨 and Next.js are now less secure than a chocolate teapot! 🍫☕️ Apparently, if you remember how to run `createnextapp`, you might be seconds away from becoming a hacker's best friend. The solution? like your life depends on it! 🛠️💻
wiz.io/blog/critical-vulnerabi




Show Original Post


03.12.2025 18:30
hn50 (@hn50@social.lansky.name)

RCE Vulnerability in React and Next.js

Link: github.com/vercel/next.js/secu
Discussion: news.ycombinator.com/item?id=4

#react




Show Original Post


03.12.2025 18:25
matdave (@matdave@floss.social)

Did everyone npm update today?

#react #nextjs




Show Original Post


03.12.2025 18:20
GripNews (@GripNews@mastodon.social)

🌗 React Server Components 驚現關鍵安全漏洞,恐致遠端程式碼執行
➤ 立即更新:React Server Components 漏洞危及伺服器安全
react.dev/blog/2025/12/03/crit
React 團隊發布重大安全警告,指出 React Server Components(RSC)中存在一項嚴重的遠端程式碼執行(RCE)漏洞,編號為 CVE-2025-55182,CVSS 評分為滿分的 10.0。此漏洞由 Lachlan Davidson 於 11 月 29 日通報,攻擊者可透過操縱傳送至 RSC 端點的資料,在未經授權的情況下遠端執行程式碼。即使應用程式未直接實作 RSC 端點,若支援 RSC,仍可能受影響。React 團隊已發布修補版本,建議使用者立即升級。文章也列出了受影響的框架(如 Next.js、React Router 等)及升級指示,並提




Show Original Post


03.12.2025 18:17
h4ckernews (@h4ckernews@mastodon.social)

Critical RCE Vulnerabilities in React and Next.js

wiz.io/blog/critical-vulnerabi

-2025-55182




Show Original Post


1 ...100 101 102 103 104 105 106 107 108 109 110 ...180
UP