Security · 7h ago
React Flight Protocol Flaw Enables Remote Code Execution
A critical vulnerability in React Server Components' Flight protocol, dubbed React2Shell, allows attackers to achieve remote code execution via deserialization sinks. The flaw carries a CVSS score of 10.0, indicating maximum severity. Durgesh Pawar details how protocol manipulation can weaponize the streaming mechanism.
Meridian48 take
While the CVSS 10.0 rating underscores the severity, the real-world impact depends on how widely the vulnerable protocol is used in production environments.
Read the full reporting
Weaponizing And Defending The React Flight Protocol: Deserialization Sinks In RSCs →
Smashing Magazine
react-server-componentsdeserialization-vulnerability