Hacker News new | ask | show | jobs
by 1vuio0pswjnm7 200 days ago
From the blog post:

"Assigned CVE-2025-55182 (React) and CVE-2025-66478 (Next.js), this flaw allows for unauthenticated remote code execution (RCE) on the server due to insecure deserialization."