
CVE-2026-39371 RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassi… https://www.cve.org/CVERecord?id=CVE-2026-39371
Post summary
The post discloses CVE-2026-39371, explaining that RedwoodSDK's server functions can be inappropriately accessed through GET requests, highlighting a new vulnerability.
