shipfeedAI news, curated daily

23:52:26 CET
20 MAY23:52:26shipfeed
pull to refreshlast sync
Just in — 30 new
§ feed · storyline

Automated React2Shell vulnerability patching is now available

Vercel Agent now automatically detects React2Shell (CVE-2025-55182) vulnerabilities in projects and generates pull requests to upgrade affected React and Next.js packages at no cost.

Dec 8 · · primary fetch1 sourceupdated Dec 8 ·

Vercel Agent now detects vulnerable packages in your project, and automatically generates pull requests with fixes to upgrade them to .patched versions Powered by Vercel's , these auto-fix upgrades are available at no cost and help teams stay secure with minimal manual effort.self-driving infrastructure is a critical remote code execution vulnerability in React Server Components that affects React 19 and frameworks that use it like Next.js. Specially crafted requests can trigger unintended code execution if your application is running a vulnerable version.

Immediate upgrades are required for all projects using affected React and Next.js releases.About React2ShellReact2Shell (CVE-2025-55182) Get the or view the .latest updates on React2Shellnew dashboard here Read more Automatic detection of vulnerable React, Next.js, and related RSC packages Automatic PR creation Full execution and verification of updates inside isolated Sandbox environments Preview links generated with PR, to manually validate updates

read full article on vercel.com
§ sources1 publication · timeline below
  1. vercel.comAutomated React2Shell vulnerability patching is now availableprimary