有人正在构建开源(OSS)工具来利用新的 Next.js 漏洞。这是一个用于反击的工具——让升级你所有 GitHub 账户中的 Next.js 应用变得傻瓜式简单。
底层使用官方 Vercel 修复工具。
2025年12月11日:Next.js 披露了多个影响使用 App Router 的 React Server Components 的关键漏洞:
https://nextjs.org/blog/cve-2025-55183-and-cve-2025-55184
curl -O https://raw.githubusercontent.com/williavs/nextjs-security-update/main/nextjs-security-update.sh
chmod +x nextjs-security-update.sh
./nextjs-security-update.sh
或直接指定账户:
./nextjs-security-update.sh myusername myorg
DRY_RUN=true ./nextjs-security-update.sh # See what would change
AUTO_PUSH=true ./nextjs-security-update.sh # Push automatically
gh(GitHub CLI)- 已认证node / npxgit推送所有更改:
cd ~/nextjs-security-updates
for d in */; do (cd "$d" && git push && echo "Pushed $d"); done
然后重新部署你的应用。