You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As of #6880, modern-js uses a vendored version of react-server-dom-webpack (19.0.0). Today (2025-12-03) Facebook disclosed a remote code execution vulnerability in this version. See:
The React team has not (yet) published specifics about how the exploit works, but given that @modern-js/render uses react-server-dom-webpack to render RSCs, it seems highly likely that it is vulnerable