Admins and defenders gird themselves against maximum-severity server vuln
Open source React executes malicious code with malformed HTML—no authentication needed. Security defenders are girding themselves in response to the disclosure of a maximum-severity vulnerability disclosed Wednesday in React Server, an open-source package that’s widely used by websites and in cloud environments. The vulnerability is easy to exploit and…