Security Fix
CVE-2025-66478 - Critical RCE in React Server Components
- Severity: Critical (CVSS 10.0)
- Fix: Updated Next.js from 15.5.2 to 15.5.7
A critical vulnerability was discovered in the React Server Components (RSC) "Flight" protocol that allows unauthenticated remote code execution (RCE) on the server due to insecure deserialization.
All users are strongly encouraged to upgrade immediately.
References
Full Changelog: 0.52.1...0.52.2