average_bitcoiner on Nostr: Web devs be aware. > A pre-authentication remote code execution vulnerability exists ...
Web devs be aware.
https://nvd.nist.gov/vuln/detail/CVE-2025-55182> A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Published at
2025-12-03 19:08:01 UTCEvent JSON
{
"id": "86cbcc4c4c70c051a78c27e2c6f44a68057aa4a291a1e0924dc67cc576515543",
"pubkey": "d3d74124ddfb5bdc61b8f18d17c3335bbb4f8c71182a35ee27314a49a4eb7b1d",
"created_at": 1764788881,
"kind": 1,
"tags": [
[
"alt",
"A short note: Web devs be aware.\nhttps://nvd.nist.gov/vuln/detai..."
],
[
"r",
"https://nvd.nist.gov/vuln/detail/CVE-2025-55182"
]
],
"content": "Web devs be aware.\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-55182\n\u003e A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.\n\n",
"sig": "51d76b4e9d536995af5ef70c821bc6a2c3e5062cc1669b8b05f7ca121afc5797b772696ee2988b25945d10606fd5aa6e97c9c4a79b8d68bb4e4e02ebbab0c4d0"
}