Security & Privacy•September 23, 2026

Security Advisory Warns of State Leakage in Misconfigured React 19 Server Actions

AppSec researchers issue guidance on preventing sensitive server tokens from leaking to client components through unvalidated React Server Action closure closures.

Official Press Release
React 19AppSecNext.jsWeb SecurityJavaScript

Cybersecurity researchers at Praetorian have issued an advisory detailing a common architectural flaw in full-stack frameworks leveraging React 19 Server Actions.

The issue occurs when server functions capture broader lexical scopes containing private environment variables or internal database connection strings, inadvertently serializing these credentials into hidden form fields or client-bound JSON payloads. Researchers recommend keeping sensitive computational logic strictly separated from client interface state.

Subscribe for Updates

Get official press announcements and version releases sent directly to your email.

Join Mailing List