- 4th December 2025
Two critical CVEs (React and Next.js) turn React Server Components into an unauthenticated remote code execution path via the “Flight” protocol. If you are running server-rendered React with RSC enabled, assume exposure until you prove otherwise and patch fast.
Francesco Cipollone
