ellipsis88.bsky.social
@ellipsis88.bsky.social
Reposted
Update on CVE-2025-66478 (React2Shell):

An npm package has been released to scan and update affected Next.js apps. Use `npx fix-react2shell-next` to update to patched versions.

All users should update as soon as possible.

More details our blog:

nextjs.org/cve-2025-66478
Security Advisory: CVE-2025-66478
A critical vulnerability (CVE-2025-66478) has been identified in the React Server Components protocol. Users should upgrade to patched versions immediately.
nextjs.org
December 6, 2025 at 4:19 PM