Prismic Announcements
·1 min read

React2Shell and Other Vulnerabilities Notice

React2Shell (CVE-2025-66478) is a critical vulnerability affecting React and Next.js websites supporting React Server Components. If your website supports React Server Components, even if they are not used, you must update your website.

Official advisory: https://nextjs.org/blog/CVE-2025-66478

Additionally, a Denial of Service vulnerability (CVE-2025-55184 and CVE-2025-67779) and Source Code Exposure vulnerability (CVE-2025-55183) affect React and Next.js websites.

Official advisory: https://nextjs.org/blog/security-update-2025-12-11

We are confident Prismic’s services are not impacted and remain secure. However, we strongly recommend checking your own React and Next.js websites.

The official repositories for Prismic’s Next.js starters and demos were patched on December 11, 2025. If you cloned or downloaded a Next.js Prismic starter or demo on or before December 11, 2025, it is critical that you update your dependencies following the official recommendation: https://nextjs.org/blog/security-update-2025-12-11

For any additional questions about React2Shell's or any other vulnerability's impact on Prismic, contact us through our Support Portal.

Addendum

This announcement originally covered just React2Shell. Since then, two additional React and Next.js vulnerabilities were shared: CVE-2025-55184, CVE-2025-67779, and CVE-2025-55183.

All of Prismic's Next.js starters and demos were re-patched on December 11, 2025. The links and dates in this blog post were updated accordingly.

Article written by

Angelo Ashmore

Senior Developer Experience Engineer at Prismic focusing on Next.js, React, and TypeScript.

More posts

Also written by

Alex Trost

Alex Trost is a front-end developer and educator from Connecticut. He's the Developer Experience Team Lead at Prismic, where he's working to make building Jamstack sites fun and easy. He also streams on Twitch to learn from and teach others about fun ways to build for the web. He writes articles and a newsletter around creative coding at Frontend Horse.

More posts
Alex Trost smiling

Join the discussion

Hit your website goals

Websites success stories from the Prismic Community

How Arcadia is Telling a Consistent Brand Story

Read Case Study

How Evri Cut their Time to Ship

Read Case Study

How Pallyy Grew Daily Visitors from 500 to 10,000

Read Case Study

From Powder to Pixels - Perfectly Planned Ski Vacations, Now Perfectly Digital

Read Case Study