Skip to content

Conversation

@dcbouius
Copy link
Contributor

@dcbouius dcbouius commented Dec 8, 2025

Summary

  • Upgrades Next.js from 15.5.3 to 15.5.7 to patch CVE-2025-66478

Security Impact

CVE-2025-66478 - Critical (CVSS 10.0) Remote Code Execution vulnerability in React Server Components.

Reference

https://nextjs.org/blog/CVE-2025-66478

Critical (CVSS 10.0) Remote Code Execution vulnerability in React Server Components.
Affects Next.js 15.x < 15.5.7.

Reference: https://nextjs.org/blog/CVE-2025-66478
@cdbartholomew cdbartholomew merged commit 0395291 into main Dec 8, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants