I got an email from Vercel urging to upgrade Next.js based project 3 days ago. POC was published 2 days ago. Today I’ve checked my logs and I could already see attack attempts.

  • PortNull@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    8
    ·
    25 days ago

    Are we still vulnerable if our app doesn’t use React Server Functions endpoints?

    Potentially. According to the React Team, even if React Server Functions are not in-use, the vulnerability is still exploitable if React Server Components are supported.