Security: Fix critical React Server Components vulnerability #11
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Security Update: Fix Critical React Server Components Vulnerability
This PR addresses a critical security vulnerability in React Server Components disclosed on December 3, 2025.
Reference: https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components
Packages Updated
react: 19.1.0 → 19.1.2react-dom: updated to 19.1.2 (to maintain compatibility)What Changed
This update patches a critical security vulnerability affecting React Server Components. All teams should prioritize reviewing and merging this PR.
Testing
This PR was automatically generated by the React vulnerability scanner.