Live data from Hacker News

Critical RCE Vulnerabilities in React and Next.js

wiz.io

61–70 of 92 posts

Re: Critical RCE Vulnerabilities in React and Next.js

#61

Earlier quoted context omitted.

So smart quotes is now an LLM tell? You know that a lot of people write in word processors that automatically replace standard quotes with smart quotes (like, say, MS Word), and that these word processors can then export HTML straight into your block or preserve the smart quotes across a copy & paste? Several blog WYSIWYG editors will also directly insert them as well.

I think what they're saying is that having both in a document is the tell.

The document doesn't have both in it. It's possible it was edited, but someone else in the thread posted the archive.org original version, and it also doesn't have smart quotes:

https://web.archive.org/web/20251203162416/https://www.wiz.i...

(Note also that you can end up with mismatched quotes if you paste in a segment of text from some other source that uses them, which is pretty common in journalism for a fast-changing story.)

Re: Critical RCE Vulnerabilities in React and Next.js

#62

Earlier quoted context omitted.

I think what they're saying is that having both in a document is the tell.

The document doesn't have both in it. It's possible it was edited, but someone else in the thread posted the archive.org original version, and it also doesn't have smart quotes: https://web.archive.org/web/20251203162416/https://www.wiz.i... (Note also that you can end up with mismatched quotes if you paste in a segment of text from some other source that uses them, which is pretty common in journalism for a fast-cha…

https://archive.md/2025.12.03-165833/https://www.wiz.io/blog...

Mismatched smart quotes are visible in this archive.

Re: Critical RCE Vulnerabilities in React and Next.js

#63
post #49

Basically, JavaScript should not be running on servers. Vulnerabilities caused by shoddy JS are a lot more impactful to a server since multiple users will be served by the same runtime instance.

It's not JavaScript by itself. It's unsafe coding practices that blend production and development code. The bug here is in the hot reloading code. It should not be enabled anywhere but on developers' machines.

Not entirely true. The bug is also in the dev server, but primarily the exploitable vulnerability is in apps built for production.

Re: Critical RCE Vulnerabilities in React and Next.js

#64
post #41

Earlier quoted context omitted.

Is it so important ? It's a mix of AI and human-written. It's normal nowadays and perfectly acceptable. + it is maybe 10% AI max, which seems to be for the structure / readability, and there is legit information under.

Yeah it's important, it degrades trust in the reader if you use AI without disclosing or ensuring them the document was proofread. Same way if you read an article full of typos you lose trust in it. Those tells of AI voice undermine the author and make the reader suspicious

>Same way if you read an article full of typos you lose trust in it

Not for long! This seems like this will soon be the only way to put something on the internet without people rabidly saying its ai (at least for a few weeks, until people start prompting for typos to be included).

Re: Critical RCE Vulnerabilities in React and Next.js

#65
post #35
post #27

Earlier quoted context omitted.

It's easier for a bad actor to get an exploit, than for an operator to test his own site if the upgrade succeded

An operator might not be able to upgrade at all! Along the fixes, the advisories now need to contain detailed workarouds, firewall rules and other adhoc solutions to ensure they get quickly deployed.

I tend to agree. Cloudflare and Vercel were able to mitigate in the form of WAF rules, but it's not immediately clear what a user or vendor can do to implement mitigations themselves other than updating their dependencies (quickly!).

IMO the CVE announcement could have been better handled. This was a level 10. If other mitigations can are viable and you know about them, you have a responsibility to disclose them in order to best protect the safety of the billions of users of React applications.

I wonder how many applications are still vulnerable.

Re: Critical RCE Vulnerabilities in React and Next.js

#66

Earlier quoted context omitted.

> It just comes off as condescending. Or, … they're just citing the source for the information, so that, in case you aren't aware as to where to find them, now you are. I think that's a doubly reasonable thing to do, given that your account is new, too.

> in case you aren't aware as to where to find them The guidelines are linked at the bottom of every page, and directly underneath the comment box on new accounts. I also, perhaps surprisingly, know how to google "hn guidelines". Or ask chatgpt. Or reply "where's that piece of information from?". > I think that's a doubly reasonable thing to do, given that your account is new, too. People link the guidelines and, lik…

> If you're talking to someone in real life, or professional emails, or whatever and you provide citations for commonly known things/definitions/etc.... you're being condescending.

If you're commenting on a public forum and you provide citations for commonly known things/definitions/etc., you're supplying the source of your claims for people who may be unaware. You are not the only reader of their comment (nor this one), even if it is in direct reply to yours.

Re: Critical RCE Vulnerabilities in React and Next.js

#67

Earlier quoted context omitted.

> It just comes off as condescending. Or, … they're just citing the source for the information, so that, in case you aren't aware as to where to find them, now you are. I think that's a doubly reasonable thing to do, given that your account is new, too.

> in case you aren't aware as to where to find them The guidelines are linked at the bottom of every page, and directly underneath the comment box on new accounts. I also, perhaps surprisingly, know how to google "hn guidelines". Or ask chatgpt. Or reply "where's that piece of information from?". > I think that's a doubly reasonable thing to do, given that your account is new, too. People link the guidelines and, lik…

[deleted]

Re: Critical RCE Vulnerabilities in React and Next.js

#68
post #28

Earlier quoted context omitted.

Hackernews' submission guidelines clearly state: "Please submit the original source. If a post reports on something found on another site, submit the latter." [0] The Wiz post has significantly changed since it was first published (and how it looked when first posted to HN), FYI -- see [1]. When it was published, it was a summary of the React announcement, and was somehow longer than the original and yet provided les…

[flagged]

    Dear jfindper,

    I hope this professional email finds you well.
    
    Would you mind reading about HN's approach to comments and site guidelines?
    
    https://news.ycombinator.com/newswelcome.html
    
    Please don't fulminate. Please don't sneer, including at the rest of the community.
    
    Kind regards,
    
    A. Webshitter

Re: Critical RCE Vulnerabilities in React and Next.js

#69
post #56

Earlier quoted context omitted.

When I saw "WIZ Research - Critical Vulnerabilities in React and Next.js" on the big image banner, I immediately thought that Wiz found the vulnerability.

When Reuters has an article that says "Reuters Business - Interest rates going up", do you think Reuters made the interest rates go up themselves or that they are reporting on the interest rates?

Reuters isn’t a bank. Wiz is a security company so they have a greater responsibility to distinguish between their own original work and discoveries made by other researchers.

Re: Critical RCE Vulnerabilities in React and Next.js

#70

Earlier quoted context omitted.

[flagged]

Dear jfindper, I hope this professional email finds you well. Would you mind reading about HN's approach to comments and site guidelines? https://news.ycombinator.com/newswelcome.html Please don't fulminate. Please don't sneer, including at the rest of the community. Kind regards, A. Webshitter

Posting the same joke twice does not equal twice as funny.
Post reply on HN