zlacker

[parent] [thread] 1 comments
1. brown9+(OP)[view] [source] 2025-12-03 21:48:56
so any package could declare some modules as “use server” and they’d be callable, whether the RSC server owner wanted them to or not? That seems less than ideal.
replies(1): >>clucki+5c1
2. clucki+5c1[view] [source] 2025-12-04 08:47:19
>>brown9+(OP)
The vulnerability exists in the transport mechanism in affected versions. Default installs without custom code are also vulnerable even if they do not use any server components / server functions.
[go to top]