A critical vulnerability has been discovered in React Server Components and frameworks like Next.js, allowing an unauthenticated external attacker to run arbitrary code.
Google’s web crawlers have come a long way in recent years in their ability to fetch and execute JavaScript. However, JavaScript integration remains tricky when setting up the front end of a web app.
Critical vulnerability in React library should be treated by IT as they did Log4j - as an emergency, warns one expert.