@vitejs/plugin-rsc vendors react-server-dom-webpack, which contained a vulnerability in versions prior to 19.2.4. See details in React repository's advisory https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg
Upgrade immediately to @vitejs/plugin-rsc@0.5.23 or later.
{
"cwe_ids": [
"CWE-400"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-10T15:36:00Z",
"nvd_published_at": null,
"severity": "HIGH"
}