Skip to content

Conversation

@ctate
Copy link

@ctate ctate commented Dec 8, 2025

This repository is listed on Vercel Templates.

It uses a version of Next.js that is vulnerable to React2Shell. This PR upgrades the template to the nearest patched version.

We have temporarily disabled the ability for developers to deploy this template.

Action required

Please review the changes and run a quick test. If everything looks correct, you can merge this PR.
If you prefer to upgrade manually, feel free to close this and apply your own fix.

Thank you.

This upgrade fixes CVE-2025-55182, a React Server Components RCE vulnerability.
@vercel
Copy link

vercel bot commented Dec 8, 2025

@ctate is attempting to deploy a commit to the timlrx's projects Team on Vercel.

A member of the Team first needs to authorize it.

@ctate ctate closed this Dec 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant