frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

RCE Vulnerability in React and Next.js

https://github.com/vercel/next.js/security/advisories/GHSA-9qr9-h5gf-34mp
53•rayhaanj•1h ago

Comments

AgentK20•1h ago
CVE 10.0 is bonkers for a project this widely used
rs_rs_rs_rs_rs•16m ago
React is widely used, react server components not so much.
_jab•4m ago
Next.js is still pretty damn widely used.
bitbasher•52m ago
It's almost like trying to magically wire up your frontend to the backend through magical functions is a bad idea.
baiwl•36m ago
Look at the money they’ve made to see if it was a bad idea or not.
bitbasher•29m ago
I don't think money is a good proxy for idea quality. AI? Blockchain? Crime in general? Plenty of bad ideas make a whole lot of money.
dizlexic•10m ago
Enron made boat loads.
dizlexic•10m ago
ikr, no way this could have been predicted and warned about for months and months before now.
ajross•48m ago
The CVE says the that flaw is in React Server Components, which implies strongly that this is a RCE on the backend (!!), not the client.
phelm•38m ago
More detail in the React Blog post here https://react.dev/blog/2025/12/03/critical-security-vulnerab...
embedding-shape•38m ago
From Facebook/Meta: https://www.facebook.com/security/advisories/cve-2025-55182

> A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

React's own words: https://react.dev/blog/2025/12/03/critical-security-vulnerab...

> React Server Functions allow a client to call a function on a server. React provides integration points and tools that frameworks and bundlers use to help React code run on both the client and the server. React translates requests on the client into HTTP requests which are forwarded to a server. On the server, React translates the HTTP request into a function call and returns the needed data to the client.

> An unauthenticated attacker could craft a malicious HTTP request to any Server Function endpoint that, when deserialized by React, achieves remote code execution on the server. Further details of the vulnerability will be provided after the rollout of the fix is complete.

nickthegreek•37m ago
dupe: https://news.ycombinator.com/item?id=46136067
anonymars•10m ago
Hey, just wanted to thank you for your recommendation for The Rehearsal season 2. It was deep, funny, crazy, etc.

Sorry for the off topic, but figured this would be the least offensive spot to commit the faux pas

benmmurphy•26m ago
I suspect the commit to fix is:

https://github.com/facebook/react/commit/bbed0b0ee64b89353a4...

and it looks like its been squashed with some other stuff to hide it or maybe there are other problems as well.

this pattern appears 4 times and looks like it is reducing the functions that are exposed to the 'whitelist'. i presume the modules have dangerous functions in the prototype chain and clients were able to invoke them.

      -  return moduleExports[metadata.name];
      +  if (hasOwnProperty.call(moduleExports, metadata.name)) {
      +    return moduleExports[metadata.name];
      +  }
      +  return (undefined: any);
hackhomelab•4m ago
It could also be https://github.com/facebook/react/commit/7dc903cd29dac55efb4... ("This also fixes a critical security vulnerability.")
dizlexic•11m ago
AHAHAHAHAHA, I'm sorry but we all knew this would happen.

I'm just laughing because I called it when they were in the "random idea x posts" about use server.

They'll fix it, but this was what we were warning about.

Congressional lawmakers 47% pts better at picking stocks

https://www.nber.org/papers/w34524
586•mhb•3h ago•359 comments

Steam Deck lead reveals Valve is funding ARM compatibility of Windows games

https://frvr.com/blog/news/steam-deck-lead-reveals-valve-is-funding-arm-compatibility-of-windows-...
60•OsrsNeedsf2P•35m ago•20 comments

MinIO is now in maintenance-mode

https://github.com/minio/minio/commit/27742d469462e1561c776f88ca7a1f26816d69e2
136•hajtom•1h ago•86 comments

RCE Vulnerability in React and Next.js

https://github.com/vercel/next.js/security/advisories/GHSA-9qr9-h5gf-34mp
56•rayhaanj•1h ago•16 comments

1D Conway's Life glider found, 3.7B cells long

https://conwaylife.com/forums/viewtopic.php?&p=222136#p222136
8•nooks•10m ago•1 comments

You Can't Fool the Optimizer

https://xania.org/202512/03-more-adding-integers
170•HeliumHydride•5h ago•93 comments

Rocketable (YC W25) is hiring a founding engineer to automate software companies

https://www.ycombinator.com/companies/rocketable/jobs/CArgzmX-founding-engineer-automation-platform
1•alanwells•34m ago

How to Synthesize a House Loop

https://loopmaster.xyz/tutorials/how-to-synthesize-a-house-loop
58•stagas•5d ago•14 comments

GSWT: Gaussian Splatting Wang Tiles

https://yunfan.zone/gswt_webpage/
46•klaussilveira•2h ago•11 comments

Critical RCE Vulnerabilities in React and Next.js

https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182
110•gonepivoting•1h ago•50 comments

A Look at Rust from 2012

https://purplesyringa.moe/blog/a-look-at-rust-from-2012/
110•todsacerdoti•1w ago•23 comments

Why are my headphones buzzing whenever I run my game?

https://alexene.dev/2025/12/03/Why-do-my-headphones-buzz-when-i-run-my-game.html
63•pacificat0r•2h ago•53 comments

Critical Security Vulnerability in React Server Components

https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components
34•nomaxx117•1h ago•3 comments

Are we repeating the telecoms crash with AI datacenters?

https://martinalderson.com/posts/are-we-really-repeating-the-telecoms-crash-with-ai-datacenters/
53•davedx•6h ago•16 comments

Zig quits GitHub, says Microsoft's AI obsession has ruined the service

https://www.theregister.com/2025/12/02/zig_quits_github_microsoft_ai_obsession/
743•Brajeshwar•9h ago•400 comments

Interview with RollerCoaster Tycoon's Creator, Chris Sawyer (2024)

https://medium.com/atari-club/interview-with-rollercoaster-tycoons-creator-chris-sawyer-684a0efb0f13
224•areoform•13h ago•40 comments

Helldivers 2 devs slash install size from 154GB to 23GB

https://www.tomshardware.com/video-games/pc-gaming/helldivers-2-install-size-slashed-from-154gb-t...
251•doener•4h ago•183 comments

The Writing Is on the Wall for Handwriting Recognition

https://newsletter.dancohen.org/archive/the-writing-is-on-the-wall-for-handwriting-recognition/
137•speckx•1w ago•72 comments

universal-tbxi-patchset: Mac OS New World ROM patchset to boot System 7.5

https://github.com/Wack0/universal-tbxi-patchset
19•classichasclass•4d ago•2 comments

Super fast aggregations in PostgreSQL 19

https://www.cybertec-postgresql.com/en/super-fast-aggregations-in-postgresql-19/
182•jnord•1w ago•17 comments

Mapping Every Dollar of America's $5T Healthcare System

https://healthisotherpeople.substack.com/p/an-abominable-creature
102•brandonb•2h ago•88 comments

VA staff flag dangerous errors in Oracle-built electronic health record

https://www.washingtonpost.com/investigations/2025/12/03/veterans-administration-va-hospitals-hea...
39•ksenzee•2h ago•3 comments

Anthropic acquires Bun

https://bun.com/blog/bun-joins-anthropic
2067•ryanvogel•23h ago•986 comments

Anthropic reportedly preparing for $300B IPO

https://vechron.com/2025/12/anthropic-hires-wilson-sonsini-ipo-2026-openai-race/
132•GeorgeWoff25•7h ago•99 comments

The "Mad Men" in 4K on HBO Max Debacle

http://fxrant.blogspot.com/2025/12/the-mad-men-in-4k-on-hbo-max-debacle.html
298•tosh•5h ago•128 comments

Paged Out

https://pagedout.institute
526•varjag•21h ago•56 comments

Researchers Find Microbe Capable of Producing Oxygen from Martian Soil

https://scienceclock.com/microbe-that-could-turn-martian-dust-into-oxygen/
77•ashishgupta2209•11h ago•32 comments

AI agents break rules under everyday pressure

https://spectrum.ieee.org/ai-agents-safety
261•pseudolus•6d ago•142 comments

Microsoft lowers AI software growth targets

https://finance.yahoo.com/news/microsoft-lowers-ai-software-sales-141531121.html
78•ramoz•2h ago•60 comments

Optimizations in C++ compilers: a practical journey

https://queue.acm.org/detail.cfm?id=3372264
18•fanf2•4d ago•0 comments