priyanshuv3.bsky.social
priyanshuv3.bsky.social
priyanshuv3.bsky.social
@priyanshuv3.bsky.social
Reposted by priyanshuv3.bsky.social
Update on CVE-2025-66478 (React2Shell):

An npm package has been released to scan and update affected Next.js apps. Use `npx fix-react2shell-next` to update to patched versions.

All users should update as soon as possible.

More details our blog:

nextjs.org/cve-2025-66478
Security Advisory: CVE-2025-66478
A critical vulnerability (CVE-2025-66478) has been identified in the React Server Components protocol. Users should upgrade to patched versions immediately.
nextjs.org
December 6, 2025 at 4:19 PM
Reposted by priyanshuv3.bsky.social
There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it.

A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately.

react.dev/blog/2025/12...
Critical Security Vulnerability in React Server Components – React
The library for web and native user interfaces
react.dev
December 3, 2025 at 3:45 PM