Discussion
Loading...

#Tag

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
heise online boosted
heise Security
@heisec@social.heise.de  ·  activity timestamp 6 days ago

Jetzt patchen! Attacken auf React2Shell-Lücke laufen an

Aufgrund von laufenden Attacken sollten Admins ihre React-Server zügig auf den aktuellen Stand bringen.

https://www.heise.de/news/Jetzt-patchen-Attacken-auf-React2Shell-Luecke-laufen-an-11103976.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#Cyberangriff #Exploit #IT #React #Security #Sicherheitslücken #Updates #news

https://social.heise.de/tags/Sicherheitsl%C3%BCcken
  • Copy link
  • Flag this post
  • Block
Agaric Tech Collective boosted
Drupal Association
@drupalassoc@mastodon.social  ·  activity timestamp 7 days ago

👋 Say hello to Drupal Canvas, a visual page builder now live for early testing. Build beautiful custom websites using a modern drag-and-drop, component-based interface. Try it and join the conversation.

🚀 This is the first stable milestone in a massive community-driven effort to modernize building with Drupal.

🔗 Learn more at https://www.drupal.org/blog/drupal-canvas-is-now-available-inside-drupals-new-visual-page-builder

#Drupal #DrupalCanvas #VisualBuilding #CMS #React

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
Cat 🐈🥗 (D.Burch) :blobcatrainbow: boosted
Stacey Holleran
@StaceyHolleran@infosec.exchange  ·  activity timestamp 7 days ago

“Working weaponized” POC exploit now available…https://www.rapid7.com/blog/post/etr-react2shell-cve-2025-55182-critical-unauthenticated-rce-affecting-react-server-components/ #react

  • Copy link
  • Flag this post
  • Block
Fediverse Development boosted
Drupal
@drupal@mastodon.social  ·  activity timestamp 7 days ago

👋 Say hello to Drupal Canvas, a visual page builder now live for early testing. Build beautiful custom websites using a modern drag-and-drop, component-based interface. Try it and join the conversation.

🚀 This is the first stable milestone in a massive community-driven effort to modernize building with Drupal.

🔗 Learn more at https://www.drupal.org/blog/drupal-canvas-is-now-available-inside-drupals-new-visual-page-builder

#Drupal #DrupalCanvas #VisualBuilding #CMS #React

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
heise online boosted
heise Security
@heisec@social.heise.de  ·  activity timestamp last week

Jetzt patchen! Kritische Schadcodelücke bedroht React

Die JavaScript-Programmbibliothek React und bestimmte damit erstellte Apps sind verwundbar. Sicherheitsupdates stehen zum Download bereit.

https://www.heise.de/news/Jetzt-patchen-Kritische-Schadcodeluecke-bedroht-React-11102366.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#IT #Patchday #React #Security #Sicherheitslücken #Updates #news

Security

Kritische Schadcodelücke bedroht React

Die JavaScript-Programmbibliothek React und bestimmte damit erstellte Apps sind verwundbar. Sicherheitsupdates stehen zum Download bereit.
https://social.heise.de/tags/Sicherheitsl%C3%BCcken
  • Copy link
  • Flag this post
  • Block
Pedro Piñera boosted
Peter Kröner
@sir_pepe@mastodon.social  ·  activity timestamp last week

Critical Security Vulnerability in #React Server Components 🍿

https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

#webdev #javascript

  • Copy link
  • Flag this post
  • Block
Kat Marchán 🐈 boosted
Friday Front-End
@fridayfrontend@hachyderm.io  ·  activity timestamp last week

Why use #React? "This isn’t a rhetorical question. I genuinely want to know why devs choose to build using React. There are many reasons. Alas, none of them relate directly to user experience, other than productive devs will make better websites. (Citation needed.)" https://adactio.com/journal/22265

Why use React?

Or, more precisely, why use React *in the browser*?
⁂
More from
Jeremy Keith
  • Copy link
  • Flag this post
  • Block
heise Security
@heisec@social.heise.de  ·  activity timestamp 6 days ago

Jetzt patchen! Attacken auf React2Shell-Lücke laufen an

Aufgrund von laufenden Attacken sollten Admins ihre React-Server zügig auf den aktuellen Stand bringen.

https://www.heise.de/news/Jetzt-patchen-Attacken-auf-React2Shell-Luecke-laufen-an-11103976.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#Cyberangriff #Exploit #IT #React #Security #Sicherheitslücken #Updates #news

https://social.heise.de/tags/Sicherheitsl%C3%BCcken
  • Copy link
  • Flag this post
  • Block
Stacey Holleran
@StaceyHolleran@infosec.exchange  ·  activity timestamp 7 days ago

“Working weaponized” POC exploit now available…https://www.rapid7.com/blog/post/etr-react2shell-cve-2025-55182-critical-unauthenticated-rce-affecting-react-server-components/ #react

  • Copy link
  • Flag this post
  • Block
nullagent
@nullagent@partyon.xyz  ·  activity timestamp last week

UPDATE - It turns out this "proof of concept" was AI slop code where the AI just made a super vulnerable server instead of any exploit demo. Bc, of course it did.

Original:

There's an epic react server component RCE exploit making the rounds today.

A proof of concept just dropped. Probably wanna patch this rapidly.

https://github.com/ejpir/CVE-2025-55182-poc/tree/main

#React #Javascript #Cybersecurity #breaking

nullagent
@nullagent@partyon.xyz replied  ·  activity timestamp 7 days ago

And to be clear this is a real vulnerability in React which still ought to be patched.

More details on these vulnerablities and how to mitigate is linked below 👇🏿

https://react2shell.com

#React2Shell #react #javascript #nodejs #cybersecurity

  • Copy link
  • Flag this comment
  • Block
Drupal Association
@drupalassoc@mastodon.social  ·  activity timestamp 7 days ago

👋 Say hello to Drupal Canvas, a visual page builder now live for early testing. Build beautiful custom websites using a modern drag-and-drop, component-based interface. Try it and join the conversation.

🚀 This is the first stable milestone in a massive community-driven effort to modernize building with Drupal.

🔗 Learn more at https://www.drupal.org/blog/drupal-canvas-is-now-available-inside-drupals-new-visual-page-builder

#Drupal #DrupalCanvas #VisualBuilding #CMS #React

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
Drupal
@drupal@mastodon.social  ·  activity timestamp 7 days ago

👋 Say hello to Drupal Canvas, a visual page builder now live for early testing. Build beautiful custom websites using a modern drag-and-drop, component-based interface. Try it and join the conversation.

🚀 This is the first stable milestone in a massive community-driven effort to modernize building with Drupal.

🔗 Learn more at https://www.drupal.org/blog/drupal-canvas-is-now-available-inside-drupals-new-visual-page-builder

#Drupal #DrupalCanvas #VisualBuilding #CMS #React

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
Konstantin 🔭
@konstantin@hachyderm.io  ·  activity timestamp last week

I will never understand the urge the use a library designed to provide reactive DOM updates as a server framework. Here I am, wasting time parametrising my queries while some are shipping unprotected “eval()” in what looks like a very abstracted gRPC service.

https://github.com/vercel/next.js/security/advisories/GHSA-9qr9-h5gf-34mp

#WebDev #React #NextJS

  • Copy link
  • Flag this post
  • Block
heise Security
@heisec@social.heise.de  ·  activity timestamp last week

Jetzt patchen! Kritische Schadcodelücke bedroht React

Die JavaScript-Programmbibliothek React und bestimmte damit erstellte Apps sind verwundbar. Sicherheitsupdates stehen zum Download bereit.

https://www.heise.de/news/Jetzt-patchen-Kritische-Schadcodeluecke-bedroht-React-11102366.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#IT #Patchday #React #Security #Sicherheitslücken #Updates #news

Security

Kritische Schadcodelücke bedroht React

Die JavaScript-Programmbibliothek React und bestimmte damit erstellte Apps sind verwundbar. Sicherheitsupdates stehen zum Download bereit.
https://social.heise.de/tags/Sicherheitsl%C3%BCcken
  • Copy link
  • Flag this post
  • Block
nullagent
@nullagent@partyon.xyz  ·  activity timestamp last week

UPDATE - It turns out this "proof of concept" was AI slop code where the AI just made a super vulnerable server instead of any exploit demo. Bc, of course it did.

Original:

There's an epic react server component RCE exploit making the rounds today.

A proof of concept just dropped. Probably wanna patch this rapidly.

https://github.com/ejpir/CVE-2025-55182-poc/tree/main

#React #Javascript #Cybersecurity #breaking

  • Copy link
  • Flag this post
  • Block
Peter Kröner
@sir_pepe@mastodon.social  ·  activity timestamp last week

Critical Security Vulnerability in #React Server Components 🍿

https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

#webdev #javascript

  • Copy link
  • Flag this post
  • Block
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp last week

Critical RCE Vulnerabilities in React and Next.js

https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182

#HackerNews #CriticalRCE #Vulnerabilities #React #Nextjs #Cybersecurity #Vulnerabilities #CVE-2025-55182

wiz.io

Critical RCE Vulnerabilities Discovered in React & Next.js | Wiz Blog

React and Next.js are exposed to critical unauthenticated RCE via CVE-2025-55182 and CVE-2025-66478. Learn which versions are impacted and how to mitigate.
  • Copy link
  • Flag this post
  • Block
Friday Front-End
@fridayfrontend@hachyderm.io  ·  activity timestamp last week

Why use #React? "This isn’t a rhetorical question. I genuinely want to know why devs choose to build using React. There are many reasons. Alas, none of them relate directly to user experience, other than productive devs will make better websites. (Citation needed.)" https://adactio.com/journal/22265

Why use React?

Or, more precisely, why use React *in the browser*?
⁂
More from
Jeremy Keith
  • Copy link
  • Flag this post
  • Block
Vincent Tunru
@VincentTunru@fosstodon.org  ·  activity timestamp 3 weeks ago

@danabra.mov What I haven't read much about is what bounds the cache size, or more importantly: can I be confident that a process won't crash with an out of memory error caused by using Cache Components?

#React #NextJS

  • Copy link
  • Flag this post
  • Block
Claudius Link boosted
lichen
@lichen@bananachips.club  ·  activity timestamp 3 weeks ago

github.com##.AppHeader-CopilotChat
github.com# #copilot-dashboard-entrypoint
github.com##.prc-ButtonGroup-ButtonGroup-vcMeG.DiffLinesMenu-module__diff-button-container--UrMbh
github.com##.DiffHeaderAskCopilotButton-module__askCopilotButton--XnBQK.prc-Button-ButtonBase-c50BI
github.com## #copilot-md-menu-anchor-new_comment_field
github.com# #a[href^="https://copilot-workspace.githubnext.com"]
github.com## #copilot-md-menu-anchor-pull_request_body
github.com##.lnwIhU.Box-sc-g0xbh4-0 > .octicon-copilot.octicon > path
github.com# #li:has(> ul > li#query-builder-test-result-ask-copilot)
github.com# #li.ActionList-sectionDivider[aria-hidden="true"]
github.com# #div:has(> button[data-testid="copilot-ask-menu"])
github.com# #div[data-test-id="copilot-actions-chat-button"]
github.com# #div.dropdown-divider:has(+span[data-target="copilot-diff-entry.menuItemsSlot"])
github.com# #span[data-target="copilot-diff-entry.menuItemsSlot"]
github.com# #react-partial[partial-name="copilot-code-chat"]
github.com##.copilotPreview__container
github.com# #button[id^="copilot-md-menu-anchor"]
github.com# #div:has(> button[id^="copilot-md-menu-anchor"]) + hr
github.com# #li:has(> ul > li#query-builder-test-result-chat-with-copilot)
github.com# #span:has(> p > span[data-assignee-name="Copilot"])
github.com# #div:has(> div > div > a[data-testid="open-in-copilot-agent-button"])
github.com# #command-palette-item[data-item-id="2918418660"]
github.com# #li.prc-ActionList-Divider-rsZFG
github.com# #li:has-text(/Ask about this diff/)
github.com# #div[class*="CopilotWorkspaceButton"]
github.com# #li[class="ActionListItem ActionListItem--hasSubItem"]:has(ul > li[data-item-id="repo_settings_copilot_swe_agent"])
github.com# #svg.octicon.octicon-copilot
github.com# #span[class="ActionListItem-label"]:has-text(Copilot)
github.com# #li:has(> div > span:has-text(/Explain error/))
github.com# #div[class*="CopilotAgentModeButton"]
github.com# #button:has(> span:has-text(/Try the new experience/))
github.com# #g-emoji[alias="sparkles"]
github.com# #inline-machine-translation

  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.8 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login