[GHSA-9qr9-h5gf-34mp] Next.js is vulnerable to RCE in React flight protocol #6529
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Updates
Comments
Please add CVE-2025-55182 as an alias for this issue (instead of CVE ID - No known CVE)as it is referenced in the description and references. Additionally, NVD includes the next package for CVE-2025-55182 - https://nvd.nist.gov/vuln/detail/CVE-2025-55182
Note- Added a reference to get the "change" accepted. Please feel free to remove, but it is relevant.