Skip to content
Discussion options

You must be logged in to vote

Yes, Rallly is built with Next.js and so it was vulnerable to the React2Shell CVE. I updated the vulnerable dependencies the day the CVE was announced and released a patch for self-hosters with instructions to update immediately.

I've gotten a number of reports now from users running vulnerable versions and it's clear that I need a better way to communicate these sorts of issues to administrators of self-hosted instances. I'm open to suggestions on how this should be communicated.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@david-uhlig
Comment options

Answer selected by lukevella
Comment options

You must be logged in to vote
1 reply
@lukevella
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants
Converted from issue

This discussion was converted from issue #2064 on December 10, 2025 09:32.