10.0 CVE on React and it's literally just object prototype pollution that can be used for RCE, what are we doing man
@mary_ext oh someone found the actual bug? not surprised it's been hours but i hadn't seen details
@leo I couldn't sleep so two hours after the vuln reveal I dug into the diff, it was really obvious. I figured out how it could've worked but I've yet to find the place where the second function call could've happened (Function("...")())