Vercel ChangelogDec 8, 2025, 1:00 PMimportant 85

Vercel 推出自動化 React2Shell 漏洞修復功能

Original: Automated React2Shell vulnerability patching is now available

Vercel has officially announced that fully automated remediation and protection against the "React2Shell" security vulnerability is now…

Vercel 針對嚴重的「React2Shell」遠端程式碼執行(RCE)漏洞,推出了平台層級的自動化修復機制。此功能會自動在 Vercel 託管環境中偵測並攔截惡意攻擊,或在建置時套用安全補丁。開發者無需手動修改程式碼、更新依賴或重新部署,即可確保 Next.js 與 React 專案的安全,極大地降低了安全維護成本並提供即時防護。

Vercel has officially announced that fully automated remediation and protection against the "React2Shell" security vulnerability is now available. React2Shell is a serious security vulnerability targeting server-side rendering technologies such as React Server Components (RSC) or Next.js Server Actions, through which attackers may execute arbitrary commands on the server (Remote Code Execution, RCE).

Full summary

Free shows the 3-line summary; Pro unlocks the full deep summary (~300 words) so you never have to click through.

See Pro plans →

Want the original English / full article?

Read on Vercel Changelog →

Summaries are AI-generated; the original article is authoritative.