Critical Security Vulnerability Announced in React Server Components
Key point
A critical security vulnerability has been discovered in React Server Components, requiring the attention of React and Next.js users.
Details
A critical security vulnerability has been announced in React Server Components. This vulnerability affects both React and Vercel's Next.js.
The specific affected versions are as follows:
- react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack: versions 19.0, 19.1.0, 19.1.1, 19.2.0
- Next.js: versions ≥14.3.0-canary.77, ≥15, ≥16
For Replit applications, most are safe, but apps created with the "Mobile app [beta]" option may be vulnerable. Replit has applied protective measures via Google Cloud Armor, and has also completed a patch for that option, so newly created apps are not affected.
To resolve the vulnerability, users should upgrade their Next.js and react-server-dom-* dependencies to the latest versions. Users can check whether their applications are affected via the Security and Privacy Scanner in the Replit workspace.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.