Critical RSC flaws in React and Next.js enable unauthenticated remote code execution; users should update to patched versions now.
And the earlier React2Shell patch is vulnerable If you're running React Server Components, you just can't catch a break. In ...
In early December 2025, the React core team disclosed two new vulnerabilities affecting React Server Components (RSC). These issues – Denial-of-Service and Source Code Exposure were found by security ...