Addresses CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - CVSS Score: 10.0 (Critical) - Allows unauthenticated remote code execution via RSC payloads Updates: - Next.js: 16.0.3 → 16.0.7 - React: 19.2.0 → 19.2.1 - react-dom: 19.2.0 → 19.2.1 References: - https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components - https://nextjs.org/blog/CVE-2025-66478 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
414 KiB
414 KiB