Hahn-Solo Product Management
  • Dashboard
  • Technologies
  • Competitors
  • Tasks
Theme
Basic Information
Status
Open
Priority
Now
Category
Security
Repo
JSS PM
Effort
Trivial
Task ID
T-1CAF4BA7
Details
Publish Security Advisory for React/Next.js CVEs
Create a GitHub Security Advisory on the `Sitecore/jss` repository documenting CVE-2025-55182 (CVSS 10.0, RCE) and CVE-2026-23864 (CVSS 7.5, DoS) impact on JSS Next.js deployments. Include minimum safe versions: React >=19.2.4, Next.js >=16.1.5. Link to upstream React and Next.js advisories.
Why
Active exploitation of CVE-2025-55182 continues (766+ hosts breached per The Hacker News, April 2026). JSS consumers need explicit guidance that their JSS Next.js apps are affected and what minimum versions to pin.
Evidence
Next.js research report; React research report; CVE-2025-55182 exploitation reports
Details
Context: CVE-2025-55182 (CVSS 10.0, RCE via React Server Components) has been actively exploited since December 2025, with 766+ hosts breached as of April 2026. CVE-2026-23864 (CVSS 7.5, DoS) was disclosed January 2026. Both affect any Next.js App Router application using React Server Components — which includes all JSS 22.x Next.js deployments. Sitecore has not published a JSS-specific advisory pointing consumers to safe minimum versions.

Steps:
1. Navigate to `https://github.com/Sitecore/jss/security/advisories/new`
2. Create advisory titled "React Server Components vulnerabilities affect JSS Next.js deployments"
3. Reference CVE-2025-55182 and CVE-2026-23864 with CVSS scores and links to upstream advisories
4. Specify affected versions: all JSS 22.x Next.js applications using React <19.2.4 or Next.js <16.1.5
5. Recommend minimum safe versions: React >=19.2.4, Next.js >=16.1.5
6. Link to the official Sitecore migration guide for Content SDK as the long-term fix
7. Pin the advisory link in the repository README

Acceptance criteria:
GitHub Security Advisory published and visible on the repo's security tab
Advisory references both CVEs with correct CVSS scores
Minimum safe dependency versions clearly stated
README links to the advisory

Risks: None identified. Publishing the advisory is a net positive for consumer trust.
Source Report
reports/product-management/jss/2026-04-05-jss-pm.md
Report date: Apr 5, 2026