Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The CVE says the that flaw is in React Server Components, which implies strongly that this is a RCE on the backend (!!), not the client.


I suspect client developers are also affected at least to the extent that they need to explain this RCE to CVE driven management.


Where else would it be? What would an RCE of the client even mean?


The term is always ambiguous. But react is generally understood as a client library and client-side vulnerabilities are hardly a new thing. XSS exists as a whole subfield of study precisely because of the difficulty of keeping site code from getting fooled by malicious input.

Basically you're technically correct with your quip, but engaging in some pretty awful security analysis. IMHO most people reading this headline are not going to understand that they need to audit their server dependencies.


it would be an RCE on your own machine :D


LCE


Bravo.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: