GHSA-vr6p-vq2p-6j74
Withdrawn Advisory
This advisory has been withdrawn because LikeC4 isn’t impacted by CVE-2025-55182 because it doesn’t ship React. React is a peer dependency.
Original Description
LikeC4 uses React and Next.js: which contain known RCE vulnerabilities, as seen in CVE-2025-55182.
[2025-12-15] Edit: the last fixes published by React were not thorough, a new set of fix releases completes the mitigation; see https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/likec4/likec4/security/advisories/GHSA-vr6p-vq2p-6j74, https://nvd.nist.gov/vuln/detail/CVE-2025-55182, https://github.com/github/advisory-database/pull/6561#issue-3745533679, https://github.com/likec4/likec4, https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components
