CVE-2025-66478:
React2Shell
Notice
This is a duplicate CVE of https://hackindex.io/vulnerabilities/CVE-2025-55182. Please visit that page for all the details and instructions.
Unauthenticated pre-auth RCE in React Server Components (RSC) Flight protocol. Root cause: unsafe deserialization of client-submitted payloads, allowing prototype pollution to reach the Node.js Function constructor.
Affects default Next.js apps (App Router), even without explicit server actions. Standard create-next-app production builds are vulnerable out of the box. Also hits Waku, React Router RSC, etc.
Affected packages:
Next.js
10
Critical risk
Compexity
low
Privileges
none
Authentication
none
Affected
15.x, 16.x, 14.3.0-canary.77
Patched
15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7 , 16.0.7