Question about CVE-2025-66478 and create-next-app #86889
Unanswered
fortenforge
asked this question in
Help
Replies: 1 comment
-
|
React 19.2.0 isn’t affected by this CVE. The vulnerability was in Next.js’ RSC and Server Actions handling, not React itself. That logic lives entirely in Next.js’ server runtime. Since create-next-app installs Next.js 16.0.7 (which includes the patch), the generated project is not vulnerable to CVE-2025-6647 even though React stays at 19.2.0. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Summary
We noticed that running:
Creates a project with:
The next version (16.0.7) includes a fix for CVE-2025-66478, but the react and react-dom versions are still vulnerable. What does this mean? Is the resulting application still vulnerable or not?
Additional information
No response
Example
No response
Beta Was this translation helpful? Give feedback.
All reactions