Skip to content

Conversation

@jdomeracki-coder
Copy link
Contributor

Reference:
https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

Please note that coder deployments aren't vulnerable since React Server Components aren't in use

@jdomeracki-coder jdomeracki-coder added the cherry-pick/v2.27 Items to be pulled in for the v2.27 release. label Dec 8, 2025
Copy link
Member

@aslilac aslilac left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I just wanna note for posterity that since we do not host a server components backend this codebase is not at all vulnerable to this CVE. There's no server to get RCE on.

but upgrading anyway is fine

@david-fraley david-fraley merged commit 1276135 into release/2.27 Dec 9, 2025
35 checks passed
@david-fraley david-fraley deleted the react-upgrade-CVE-2025-55182-2.27 branch December 9, 2025 14:44
@github-actions github-actions bot locked and limited conversation to collaborators Dec 9, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

cherry-pick/v2.27 Items to be pulled in for the v2.27 release.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants