logoalt Hacker News

AgentK20today at 4:04 PM3 repliesview on HN

CVE 10.0 is bonkers for a project this widely used


Replies

nine_ktoday at 5:49 PM

The packages affected, like [1], literally say:

> Experimental React Flight bindings for DOM using Webpack.

> Use it at your own risk.

311,955 weekly downloads though :-|

[1]: https://www.npmjs.com/package/react-server-dom-webpack

show 1 reply
j45today at 6:55 PM

The subjects of theses types of posts should report the CVSS severity as 10.0 so the PR speak can't simply deflect to what needs to be done.

show 1 reply
rs_rs_rs_rs_rstoday at 5:19 PM

React is widely used, react server components not so much.

show 1 reply