React Server Components (RSC) 中存在一个未经身份验证的远程代码执行( Remote Code Execution, RCE )漏洞,漏洞编号:CVE-2025-55182
应急解决办法:
npm install react@latest react-dom@latest react-server-dom-webpack@latest
Reference:
https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components