
Security Update: CVE-2025-66478 — What Next.js Developers Must Know
On December 3, 2025, Next.js maintainers issued a critical security advisory (CVE-2025-66478) affecting React Server Components (RSC) protocol. The flaw can lead to unauthenticated remote code execution on unpatched Next.js sites using App Router. This article breaks down the risk, affected versions, and the urgent fixes you should apply today.










