We’ve got confirmation of a working #react2shell POC being shared. We’ve verified Vercel’s Web Application Firewall is successfully blocking this known variant. We are also seeing bad actors attempt exploitation. Upgrading React & frameworks remains a top priority.
If you’re on Vercel, the WAF is on automatically. No action needed other than upgrading your deps and re-deploying.
29.6K