🦋 Live Bluesky Post

Matt Kane's avatar

Matt Kane

@mk.gg

Matt Kane

You know the drill: upgrade right now. These aren't as serious as last week's RCE, but they're still bad. Platforms are blocking these, but once again you shouldn't rely on it.

Researchers have found two new vulnerabilities in React Server Components while attempting to exploit the patches last week. These are new issues, separate from the critical CVE last week. The patch for React2Shell remains effective for the Remote Code Execution exploit.

December 11, 2025 at 9:47 PM UTC