Description
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Statistics Multiple Cross-Site Scripting Vulnerabilities (12.0.4)
MySQL CVE-2018-2573 Vulnerability (CVE-2018-2573)
Oracle Database Server Other Vulnerability (CVE-1999-0888)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2082)
Jboss EAP Incorrect Privilege Assignment Vulnerability (CVE-2026-3121)