{"id":"GHSA-vr6p-vq2p-6j74","summary":"Withdrawn Advisory: LikeC4 has RCE through vulnerable React and Next.js versions","details":"### Withdrawn Advisory\nThis advisory has been withdrawn because LikeC4 isn’t impacted by CVE-2025-55182 because it doesn’t ship React. React is a peer dependency.\n\n### Original Description\nLikeC4 uses React and Next.js: which contain known RCE vulnerabilities, as seen in CVE-2025-55182.\n\n[2025-12-15] Edit: the last fixes published by React were not thorough, a new set of fix releases completes the mitigation; see https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components","modified":"2025-12-22T16:44:05.239125Z","published":"2025-12-15T22:00:17Z","withdrawn":"2025-12-22T16:35:36Z","database_specific":{"cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2025-12-15T22:00:17Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/likec4/likec4/security/advisories/GHSA-vr6p-vq2p-6j74"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55182"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/6561#issue-3745533679"},{"type":"PACKAGE","url":"https://github.com/likec4/likec4"},{"type":"WEB","url":"https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components"}],"affected":[{"package":{"name":"likec4","ecosystem":"npm","purl":"pkg:npm/likec4"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.46.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-vr6p-vq2p-6j74/GHSA-vr6p-vq2p-6j74.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}