All Posts
News bits
Langflow、CVE-2026-33017で公開フロー構築APIに未認証RCE
CVE-2026-33017、POST /api/v1/build_public_tmp の任意data経由でexecに至る未認証RCE、CVSS 9.3、影響は1.8.1以下、修正は1.9.0以上。
Deno Sandbox発表
信頼できないコードを安全に実行するための軽量Linux microVM API。ネットワーク制御やシークレット保護機能を備え、Deno Deploy上で動作する。
React2Shellセキュリティ脆弱性
React Server Componentsの重大な脆弱性「React2Shell」(CVE-2025-55182)が公開された。CVSSスコアは10.0(Critical)。Next.jsではCVE-2025-66478として識別される。特定の条件下で、細工されたリクエストによりリモートコード実行が可能になる。
著者について
Hi there. I'm hrdtbs, a frontend expert and technical consultant. I started my career in the creative industry over 13 years ago, learning on the job as a 3DCG modeler and game engineer in the indie scene.
In 2015 I began working as a freelance web designer and engineer. I handled everything from design and development to operation and advertising, delivering comprehensive solutions for various clients.
In 2016 I joined Wemotion as CTO, where I built the engineering team from the ground up and led the development of core web and mobile applications for three years.
In 2019 I joined matsuri technologies as a Frontend Expert, and in 2020 I also began serving as a technical manager supporting streamers and content creators.
I'm so grateful to be working in this field, doing something that brings me so much joy. Thanks for stopping by.