# TMiR 2025-12: Year in review, React2Shell (RCE, DOS, SCE, oh my) Page: https://stenobird.com/podcast/this-month-in-react-5941373/tmir-2025-12-year-in-review-react2shell-rce-dos-sce-oh-my Text version: https://stenobird.com/podcast/this-month-in-react-5941373/tmir-2025-12-year-in-review-react2shell-rce-dos-sce-oh-my.md Podcast: [This Month in React](https://stenobird.com/podcast/this-month-in-react-5941373) Published: 2025-12-31T21:28:32+00:00 Episode link: https://share.transistor.fm/s/0f9a0980 Audio file: https://op3.dev/e/media.transistor.fm/0f9a0980/f7790fdd.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/this-month-in-react-5941373/episodes/tmir-2025-12-year-in-review-react2shell-rce-dos-sce-oh-my Duration seconds: 5990 ## Resource Full transcript at Reactiflux Main Content React2Shell vulnerability Initial announcement Followup denial-of-service CVE and source code exposure CVE Vercel bulletin Cloudflare Cloudflare report on exploit attempts Cloudflare outage on December 5, 2025 Tech analysis: “Flight Protocol” Vuln is carefully crafted Promise deserialization + `new Function` eval PRs: Initial fixes , Promise cycles / function toString , more Promise cycles Guillermo’s breakdown Shruti’s breakdown Comms critique “React is rainbow colored (function types)” What does this mean for React and RSC adoption going forward? When I go back and look at react.dev now \[…\] it feels half-finished React Native year in review More CSS support Expo EAS hosting RN 0.78: React 19 support Lynx launched RN 0.79: JSC moving to Community Package RN 0.80: Freezing the legacy architecture RN 0.81: Android 16 support for edge to edge 1.0 on the horizon Vega OS launched RN 0.82: Only new architecture Expo App Awards RN 0.83: New Devtools - no breaking changes React year in review CRA deprecation , new install docs (Vite\!) Styled Components Deprecated Releases: 19.2 (Activity, useEffectEvent), Compiler 1.0 Research: View Transitions canary, perf, concurrent stores , “throw a promise” deprecated (but not merged yet) “ Async React ” and the ecosystem React Foundation React growth skyrockets React Router RSC support , TanStack Start WIP RSC , Waku Dan’s RSC explainers (he had a bunch of things to say) Remix v3 Jam recap (not React but relevant) Mark went from frustrated ( CRA ) to excited (ReactConf, foundation, team efforts) ⚡ Lightning round ⚡ TS 7 progress update NPM classic tokens revoked GitHub Actions planned work Github Action pricing change and immediate about-face Stacked diffs proposal in the works ? Anthropic b… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/this-month-in-react-5941373/episodes/tmir-2025-12-year-in-review-react2shell-rce-dos-sce-oh-my/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/this-month-in-react-5941373/tmir-2025-12-year-in-review-react2shell-rce-dos-sce-oh-my.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.