Skip to content

[Bug]: remote code execution vulnerability in bundled react-server-dom-webpack #7970

@jenseng

Description

@jenseng

Version

System: *
Browsers: *

Details

As of #6880, modern-js uses a vendored version of react-server-dom-webpack (19.0.0). Today (2025-12-03) Facebook disclosed a remote code execution vulnerability in this version. See:

The React team has not (yet) published specifics about how the exploit works, but given that @modern-js/render uses react-server-dom-webpack to render RSCs, it seems highly likely that it is vulnerable

Reproduce link

https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

Reproduce Steps

See https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions