Denial of Service and Source Code Exposure in React Server Components

4 points by yashgarg


carlana

A security researcher has discovered that a malicious HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.

Dang.