Executive brief
@vitejs/plugin-rsc is a Vite plugin for building React Server Components (RSC) applications. Attackers with network access to the development server can execute arbitrary JavaScript code with Node.js privileges by injecting malicious code through RSC server function APIs, allowing them to read files, steal credentials and environment variables, or compromise other services on the developer's network.
Technical details
This is a code injection vulnerability (CWE-94) in the @vitejs/plugin-rsc development server caused by unsafe dynamic imports in RSC server function APIs (loadServerAction, decodeReply, decodeAction). The vulnerable code accepts user-controlled input from HTTP request headers and form data and passes it directly to JavaScript's import() function without validation, allowing attackers to load arbitrary modules including data URLs containing malicious code. The attack requires network access to a development server running on a network-reachable interface (especially with vite --host), with no authentication or user interaction required. An attacker can craft a POST request to the /_.rsc endpoint with specially crafted payloads to execute arbitrary Node.js code. The vulnerability is fixed in version 0.5.6.
Affected products
- Vitejs plugin-rsc <= 0.5.5
Timeline
- 2025-12-08: disclosed
- 2025-12-08: patched: Fix released in version 0.5.6
- 2025-12-09: advisory