On 03-Dec-2025, two vulnerabilities were discovered related to the React Server Components that affect React 19 and the frameworks that use it, including Next.js. Applications using affected versions of the React Server Components implementation may process untrusted input in a way that allows an attacker to perform remote code execution.
React Server components in React 19.x and Next.js 15.x/16.x with App Router
Appian has investigated these vulnerabilities and services, and determined that it is not impacted.
The following CVEs were released with additional information on the scope of the vulnerability:
This article applies to all supported versions of Appian.
Last reviewed: Dec 5, 2025