# Security Advisory: CVE-2025-66478

DevFeed: [Security Advisory: CVE-2025-66478](<https://devfeed.tech/articles/security-advisory-cve-2025-66478-3134.md>)

Original publisher: [Read original article](<https://nextjs.org/blog/CVE-2025-66478>)

Author: Sebastian Markbåge

Published: 2025-12-03T16:00:00Z

Content type: article

Language: en

Sources: [Next.js Blog](<https://devfeed.tech/sources/next-js-blog.md>)

Topics: [Next.js](<https://devfeed.tech/topics/next-js.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [React](<https://devfeed.tech/topics/react.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [react](<https://devfeed.tech/tags/react.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

This security advisory describes CVE-2025-66478, a critical vulnerability in the React Server Components protocol that affects certain Next.js applications using the App Router. Under specific conditions, attacker-controlled requests could lead to remote code execution. Users are advised to upgrade to patched Next.js releases immediately.

## Source excerpt

A critical vulnerability (CVE-2025-66478) has been identified in the React Server Components protocol. Users should upgrade to patched versions immediately.