The CVE says the that flaw is in React Server Components, which implies strongly that this is a RCE on the backend (!!), not the client.
I suspect client developers are also affected at least to the extent that they need to explain this RCE to CVE driven management.
Bravo.
Where else would it be? What would an RCE of the client even mean?
I suspect client developers are also affected at least to the extent that they need to explain this RCE to CVE driven management.