A critical vulnerability has been discovered in React Server Components and frameworks like Next.js, allowing an unauthenticated external attacker to run arbitrary code.
Cloudflare activates automatic WAF protection against a major React Server Components flaw as developers race to patch ...