top | item 46135784

Critical Security Vulnerability in React Server Components

70 points| nomaxx117 | 3 months ago |react.dev | reply

6 comments

order
[+] lioeters|3 months ago|reply
> An unauthenticated attacker could craft a malicious HTTP request to any Server Function endpoint that, when deserialized by React, achieves remote code execution on the server. ..Affected: next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk.

Oof, that's bad. Good thing I've only used RSC for static site generation and don't run it on a production server.

[+] bek-shoyatbek|3 months ago|reply
React first caused Cloudflare down with simple hook then now, a new feature server components causing an issue... I would rather be coding with HTMX....
[+] Veliladon|3 months ago|reply
It's a wonderful day on the Internet. A beautiful day for a CVSS 10 exploit!