coinbase / coinbase/onchainkit

Bug: Vercel For Management or Clients (Formal, Alarming, and Professional)

Open
#2,552 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
1k
Forks
520
Avg merge
32m
Merged PRs (30d)
2

Description

### Describe the bug and the steps to reproduce it

1. Go to https://docs.base.org/mini-apps/quickstart/create-new-miniapp
2. Click to deploy
3. Open vercel deploy screen
4. Vercel wants upper modules for next.js and others

### What's the expected behavior?

Dear Team,

Following the urgent announcement by Vercel’s Security CTO yesterday, I am writing to address a critical security emergency. A severe Remote Code Execution (RCE) vulnerability, identified as CVE-2025-55182 (React2Shell), has been discovered in React Server Components.

The risk level is extremely high. Our current Mini App version on GitHub is outdated and completely vulnerable to this exploit.

Malicious cyber attackers are currently actively scanning for and attacking servers running these older versions. While we have manually patched the issue in our local development environment, the live GitHub repository and servers remain exposed.

If we do not upgrade immediately, we face a high probability of a total system compromise or catastrophic failure. We must prioritize merging and deploying this security update instantly to prevent unauthorized access to our infrastructure.

### What version of the libraries are you using?

Mini ap next.js version 15 system require need more

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.