Security vulnerability identified with React Server Components

Incident Report for Sanity

Resolved

We have completed dependency updates per guidance from Vercel and the React team.

Sanity studio deployments are not affected and require no action.

If your Studio is deployed using Next.js, please follow the recommended steps outlined here: https://vercel.com/changelog/cve-2025-55182#resolution.
Posted Dec 04, 2025 - 22:12 UTC

Monitoring

Our team has applied the initial recommended updates from the React Team regarding the recent vulnerability. We are actively completing remaining internal package updates and closely monitoring any further guidance from React and Vercel.

Required Action for Next Studio Deployments:

Note: Sanity Studio deployments are not affected and require no action.

If your Studio is deployed using Next.js, please follow the recommended steps outlined here:
https://vercel.com/changelog/cve-2025-55182#resolution
Posted Dec 03, 2025 - 20:48 UTC

Investigating

A security vulnerability (CVE-2025-55182) affecting React Server Components (RSC) and several related packages including Next.js was disclosed today by the React Team (https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components).

Our Impact:

Vercel has already rolled out platform-level protections and preventative measures. We are acting proactively and have started rolling out fixes across our platform and services as well.

Required Action:

Sanity studio deployments are not affected and require no action.

If your Studio is deployed using Next.js, please follow the recommended steps outlined here: https://vercel.com/changelog/cve-2025-55182#resolution.
Posted Dec 03, 2025 - 19:37 UTC