🔒 Security Fix: Update React to 19.2.1 to address CVE-2025-55182 #3297
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🚨 Security Advisory
This PR addresses CVE-2025-55182, a critical remote code execution vulnerability in React Server Components.
📋 Summary
Updates React dependencies to patched version 19.2.1 that fixes a critical RCE vulnerability affecting React 19.
🔧 Changes
Dependency Updates
Files Modified
pnpm-workspace.yaml- Updated catalog versionspnpm-lock.yaml- Updated lockfile with new versions🔐 Vulnerability Details
✅ Testing
pnpm install📚 Additional Context
What was the issue?
The vulnerability existed in React Server Components (RSC) where malicious requests could potentially execute arbitrary code on the server.
Why this matters for visual-editing
This repository provides visual editing tools that may use React Server Components in integrated applications. Keeping React updated is essential for security.
Platform Protections
Note: Projects hosted on Vercel already have platform-level protections that block malicious request patterns. However, upgrading is still strongly recommended regardless of hosting provider.
🚀 Deployment Notes
This is a patch version update with no breaking changes. Safe for immediate deployment.
Recommended Actions
📖 Related
👥 Review Checklist
Priority: 🔴 CRITICAL - Merge and deploy ASAP.
cc: @sanity-io/engineering