Critical remote-code-execution vulnerability reported in React Server Components and related frameworks
A critical unauthenticated remote-code-execution vulnerability affects React Server Components; a separate notice also identifies React Server Functions and Next.js. React published fixes in versions 19.0.1, 19.1.2 and 19.2.1, while Deno says it mitigated the issue in Deno Deploy. Other affected users are urged to upgrade immediately.