Open source React executes malicious code with malformed HTML”, no authentication needed.
First seen on arstechnica.com
Jump to article: arstechnica.com/security/2025/12/admins-and-defenders-gird-themselves-against-maximum-severity-server-vulnerability/
![]()

