leal.eth 🫡 pfp
leal.eth 🫡

@leal.eth

If you're using React Server Components (Nextjs, React Router, etc.), an attacker can send a malicious request and get full remote code execution on your server. No auth needed. This effectively means that they can do anything they want. It is rated CVSS 10.0. The maximum possible!
0 reply
2 recasts
7 reactions