Skip to content

Fix React Server Components CVE vulnerabilities - #194

Merged
sidneyswift merged 1 commit into
mainfrom
vercel/react-server-components-cve-vu-raqdl6
Feb 3, 2026
Merged

Fix React Server Components CVE vulnerabilities#194
sidneyswift merged 1 commit into
mainfrom
vercel/react-server-components-cve-vu-raqdl6

Conversation

@vercel

@vercelvercelBot commented Feb 3, 2026

Copy link
Copy Markdown
Contributor

Important

This is an automatic PR generated by Vercel to help you with patching efforts. We can't guarantee it's comprehensive, and it may contain mistakes. Please review our guidance before merging these changes.

A critical remote code execution (RCE) vulnerability in React Server Components, impacting frameworks such as Next.js, was identified in the project recoup-api. The vulnerability enables unauthenticated RCE on the server via insecure deserialization in the React Flight protocol.

This issue is tracked under:

This automated pull request upgrades the affected React and Next.js packages to patched versions that fully remediate the issue.

More Info | security@vercel.com

Updated dependencies to fix Next.js and React CVE vulnerabilities.
The fix-react2shell-next tool automatically updated the following packages to their secure versions:
- next
- react-server-dom-webpack
- react-server-dom-parcel - react-server-dom-turbopack
All package.json files have been scanned and vulnerable versions have been patched to the correct fixed versions based on the official React advisory.
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
@vercel

vercelBot commented Feb 3, 2026

Copy link
Copy Markdown
ContributorAuthor

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
recoup-apiReadyReadyPreviewFeb 3, 2026 3:19am

@coderabbitai

coderabbitaiBot commented Feb 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Important

Action Needed: IP Allowlist Update

If your organization protects your Git platform with IP whitelisting, please add the new CodeRabbit IP address to your allowlist:

  • 136.113.208.247/32 (new)
  • 34.170.211.100/32
  • 35.222.179.152/32

Failure to add the new IP will result in interrupted reviews.


Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actionsBot commented Feb 3, 2026

Copy link
Copy Markdown

Braintrust eval report

Catalog Opportunity Analysis Evaluation (HEAD-1770088738)

ScoreAverageImprovementsRegressions
Catalog_availability31.1% (+31pp)4 🟢-
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration40.35s (+39.21s)-5 🔴

Catalog Songs Count Evaluation (HEAD-1770088739)

ScoreAverageImprovementsRegressions
Llm_calls4 (+0)--
Tool_calls0 (+0)--
Errors3 (+3)-3 🔴
Llm_errors1 (+1)-3 🔴
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration12.08s (+11s)-3 🔴

First Week Album Sales Evaluation (HEAD-1770088738)

ScoreAverageImprovementsRegressions
Llm_calls1 (+0)--
Tool_calls0 (+0)--
Errors1 (+1)-4 🔴
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration11.61s (+10.47s)-4 🔴

Memory & Storage Tools Evaluation (HEAD-1770088738)

ScoreAverageImprovementsRegressions
Tools_called0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration15.27s (+14.36s)-1 🔴

Monthly Listeners Tracking Evaluation (HEAD-1770088738)

ScoreAverageImprovementsRegressions
Llm_calls2 (+0)--
Tool_calls0 (+0)--
Errors2 (+2)-5 🔴
Llm_errors1 (+1)-5 🔴
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration12.48s (+11.46s)-5 🔴

Search Web Tool Evaluation (HEAD-1770088738)

ScoreAverageImprovementsRegressions
Llm_calls3 (+0)--
Tool_calls0 (+0)--
Errors2 (+2)-11 🔴
Llm_errors1 (+1)-11 🔴
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration21.42s (+20.32s)-11 🔴

Social Scraping Evaluation (HEAD-1770088738)

ScoreAverageImprovementsRegressions
Tools_called0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration20.7s (+19.58s)-6 🔴

Spotify Followers Evaluation (HEAD-1770088738)

ScoreAverageImprovementsRegressions
Llm_calls2.4 (-0.6)-1 🔴
Tool_calls0 (+0)--
Errors2 (+1)-5 🔴
Llm_errors0.8 (+0.8)-4 🔴
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration11.33s (+10.47s)-5 🔴

Spotify Tools Evaluation (HEAD-1770088738)

ScoreAverageImprovementsRegressions
Tools_called0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration23.46s (+22.38s)-2 🔴

TikTok Analytics Questions Evaluation (HEAD-1770088738)

ScoreAverageImprovementsRegressions
Question_answered0% (+0pp)--
Llm_calls0 (+0)--
Tool_calls0 (+0)--
Errors0 (+0)--
Llm_errors0 (+0)--
Tool_errors0 (+0)--
Prompt_tokens0tok (+0tok)--
Prompt_cached_tokens0tok (+0tok)--
Prompt_cache_creation_tokens0tok (+0tok)--
Completion_tokens0tok (+0tok)--
Completion_reasoning_tokens0tok (+0tok)--
Total_tokens0tok (+0tok)--
Duration13.77s (+12.68s)-2 🔴

@sidneyswift
sidneyswift marked this pull request as ready for review February 3, 2026 14:33
@sidneyswift
sidneyswift merged commit a35dc10 into mainFeb 3, 2026
5 checks passed
sweetmantech added a commit that referenced this pull request Feb 3, 2026
* Fix React Server Components CVE vulnerabilities (#194)
Updated dependencies to fix Next.js and React CVE vulnerabilities.
The fix-react2shell-next tool automatically updated the following packages to their secure versions:
- next
- react-server-dom-webpack
- react-server-dom-parcel - react-server-dom-turbopack
All package.json files have been scanned and vulnerable versions have been patched to the correct fixed versions based on the official React advisory.
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
* feat: update POST /api/sandboxes to use command execution
- Change request body from { prompt } to { command, args?, cwd? }
- Add account snapshot support for creating sandboxes from snapshots
- Update trigger payload to include command, args, cwd, sandboxId, accountId
- Return runId in response from triggered task
- Update tests to reflect new API structure
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: use correct source parameter for snapshot in Sandbox.create
The Vercel Sandbox SDK requires snapshotId to be passed via the source
parameter with type: 'snapshot', not as a direct property.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* test: update triggerRunSandboxCommand tests to use command payload
Update test payloads to match new API: command, args, cwd, sandboxId, accountId
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* refactor: use CreateSandboxParams from @vercel/sandbox SDK
- Export CreateSandboxParams type extracted from Sandbox.create signature
- Accept full SDK params instead of custom snapshotId option
- Apply sensible defaults for timeout, resources, and runtime
- Update handler to pass source object for snapshots
- Add tests for new parameter combinations
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: handle union type for CreateSandboxParams
Use 'in' operator to check for runtime/resources properties since
they don't exist on the snapshot variant of the union type.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: simplify createSandbox to spread defaults before params
Spread defaults first, then override with params. This avoids
type conflicts between snapshot and base param variants.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: handle trigger failure gracefully and always return response
- Wrap triggerRunSandboxCommand in try-catch to prevent hanging
- Return 200 with sandbox info even if trigger fails (runId omitted)
- Update JSDoc to document new command/args/cwd request format
- Update tests to reflect new graceful failure behavior
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* debug: add extensive logging to trace request flow
Add console.log at each step to identify where the request is hanging:
- Request received
- Validation
- Snapshot lookup
- Sandbox creation
- DB insert
- Task trigger
- Response building
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* chore: remove debug logging
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* refactor: rename selectAccountSnapshot.ts to selectAccountSnapshots.ts
Follow the select[TableName].ts naming convention where the table name
is account_snapshots (plural). Function name unchanged.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* refactor: rename function to selectAccountSnapshots and return array
- Rename function from selectAccountSnapshot to selectAccountSnapshots
- Remove .limit(1).single() to return full array
- Update handler to get first element from array
- Update tests with new function name and array return values
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* refactor: use Tables type from Supabase schema for account_snapshots
- Regenerate types with supabase gen types to include account_snapshots table
- Replace local AccountSnapshot interface with Tables<"account_snapshots">
- DRY: single source of truth for type definitions
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@sweetmantech@sidneyswift