Skip to content

[SECURITY] CVE-2025-66478: Critical RCE in Next.js - Immediate Patch Required #4

@vasconceloscezar

Description

@vasconceloscezar

Vulnerability Details

CVE ID: CVE-2025-66478
CVSS Score: 10.0 (Critical)
Type: Remote Code Execution (RCE)

Impact

Attackers can execute arbitrary code on servers running Next.js with App Router via malicious RSC protocol requests.

Required Action

Upgrade Next.js from 16.0.7 → 16.0.8

npm install [email protected]

Priority

CRITICAL - No workaround available. Upgrade immediately.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions