Discussion about this post

User's avatar
Neural Foundry's avatar

Good coverage of the RSC vuln chain. The incomplete fix turning into another CVE is pretty typical when deserialization logic gets patched under time pressure. The source code leak via stringified arguments is clever, though realistically most Server Functions probly don't expose enough context to make that exploitable at scale without already knowing the app architecture.

Expand full comment

No posts

Ready for more?