
proof
Also known as React2Shell, this vulnerability refers to a structural flaw in React Server Components where prototype pollution occurs during data deserialization, enabling RCE.
Affected versions are React 19.0.0, 19.1.0, 19.1.1, 19.2.0, Next.js 15.x (15.0.0 ~ 15.5.6), 16.x (16.0.0 ~ 16.0.6) and above.