# React.js Server Component vulnerabilities query

**URL:** <https://community.taiga.io/t/react-js-server-component-vulnerabilities-query/8623>\
**Category:** Troubleshooting\
**Created:** [December 3, 2025, 7:59pm UTC](https://community.taiga.io/t/react-js-server-component-vulnerabilities-query/8623 "2025-12-03T19:59:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mig5](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/mig5/32/3153_2.png) [@mig5](https://community.taiga.io/u/mig5)\
**Post date:** [December 3, 2025, 7:59pm UTC](https://community.taiga.io/t/react-js-server-component-vulnerabilities-query/8623/1 "2025-12-03T19:59:27Z")

</div>

Hi Taiga team!

I’ve just been reading about [Critical Security Vulnerability in React Server Components – React](https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components) which has a level 10 CVE (remote code execution).

I know that Taiga has some NodeJS components (I think in taiga-events). I _think_ it doesn’t use React Server Components or Next.js, but I wasn’t 100% sure, and thought it best to ask here just to get some reassurance that we don’t need to do anything re: self-hosted instances?

Thanks in advance! 🙂

---

<div class="post-metadata">

**Author:** ![Charlie](https://avatars.discourse-cdn.com/v4/letter/c/d6d6ee/32.png) [@Charlie](https://community.taiga.io/u/Charlie)\
**Post date:** [December 3, 2025, 9:22pm UTC](https://community.taiga.io/t/react-js-server-component-vulnerabilities-query/8623/2 "2025-12-03T21:22:56Z")

</div>

Hi there, @mig5 !

I did a quick check just in case, and we are not using any of the affected libraries/components in our JS projects.

In any case, of course, we keep reviewing the security of Taiga and releasing patches as soon as we have them, so we recommend keeping Taiga updated. For particularly major things, we will probably warn people to update here at community besides publishing the new version.

Best!

---

<div class="post-metadata">

**Author:** ![mig5](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/mig5/32/3153_2.png) [@mig5](https://community.taiga.io/u/mig5)\
**Post date:** [December 3, 2025, 9:48pm UTC](https://community.taiga.io/t/react-js-server-component-vulnerabilities-query/8623/3 "2025-12-03T21:48:50Z")

</div>

Thanks @Charlie , appreciate the reassurance!

> In any case, of course, we keep reviewing the security of Taiga and releasing patches as soon as we have them, so we recommend keeping Taiga updated. For particularly major things, we will probably warn people to update here at community besides publishing the new version.

Indeed, and I am keen to see the upgrade to a still-supported Django hopefully soon 🙂 I realise it’s a big job. Presumably there’s nothing too concerning right now in the old Django in terms of security issues (or you’d have handled the update already). In any case, will be a relief to be on the LTS version at some stage!

Thanks to you and your team for all your work.
