NextJS Security Vulnerability
↗Next.js warns of a critical, RSC-related vulnerability (CVE-2025-66478) with CVSS 10 that enables remote code execution in unpatched apps, with explicit fixed versions and upgrade steps across 15.x, 16.x (and certain 14.3.0-canary canaries); no disable switch is available.
Dec 4, 20251%