Skip to content

Adding tested members, contributors, our ethos, supporters (improved), contact (improved)#12

Merged
mattaereal merged 13 commits intomainfrom
develop
Feb 20, 2026
Merged

Adding tested members, contributors, our ethos, supporters (improved), contact (improved)#12
mattaereal merged 13 commits intomainfrom
develop

Conversation

@mattaereal
Copy link
Contributor

No description provided.

mattaereal and others added 12 commits July 1, 2025 18:43
Co-authored-by: Ariel Vincennao <arielvincennao@hotmail.com>
> [!IMPORTANT]
> This is an automatic PR generated by Vercel to help you with patching
efforts. We can't guarantee it's comprehensive, and it may contain
mistakes. Please review our
[guidance](https://vercel.link/additional-checks) before merging these
changes.

A critical remote code execution (RCE) vulnerability in React Server
Components, impacting frameworks such as Next.js, was identified in the
project [landing-v2](https://vercel.com/theredguild/landing-v2). The
vulnerability enables unauthenticated RCE on the server via insecure
deserialization in the React Flight protocol.

This issue is tracked under:

- GitHub Security Advisory:
[GHSA-9qr9-h5gf-34mp](GHSA-9qr9-h5gf-34mp)

- React Advisory:
[CVE-2025-55182](https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components)

- Next.js Advisory:
[CVE-2025-66478](https://nextjs.org/blog/CVE-2025-66478)

This automated pull request upgrades the affected React and Next.js
packages to patched versions that fully remediate the issue.

[More Info](https://vercel.link/cve-2025-55182-automated-pr) |
security@vercel.com

Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
> [!IMPORTANT]
> This is an automatic PR generated by Vercel to help you patch known
vulnerabilities related to CVE-2025-55182 (React2Shell), CVE-2025-55183,
CVE-2025-55184, and CVE-2025-67779. We can't guarantee the PR is
comprehensive, and it may contain mistakes.

Not all projects are affected by all issues, but **patched versions are
required to ensure full remediation**.

Vercel has deployed WAF mitigations globally to help protect your
application, but upgrading remains required for complete protection.

This automated pull request updates your React, Next.js, and related
Server Components packages to versions that fix **all currently known
React Server Components vulnerabilities**, including the two newly
discovered issues.

See our [Security Bulletins](https://vercel.com/kb/bulletin/) for more
information and reach out to security@vercel.com with any questions.

Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
@mattaereal mattaereal self-assigned this Feb 20, 2026
@mattaereal mattaereal added the enhancement New feature or request label Feb 20, 2026
@vercel
Copy link
Contributor

vercel bot commented Feb 20, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
landing Ready Ready Preview, Comment Feb 20, 2026 5:13am

@mattaereal mattaereal merged commit 81e68ed into main Feb 20, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants