The Node.js security release originally planned for December 15, 2025 was delayed four times and is now scheduled for January 13, 2026. The release will include fixes for three High-severity vulnerabilities.
A command-injection vulnerability was found in Windows PowerShell's `Invoke-WebRequest` cmdlet. When fetching a web page, embedded scripts could be executed.
A summary of how to verify impact and the mitigation steps for the CVSS 10.0 React2Shell vulnerability (CVE-2025-55182 / CVE-2025-66478), plus additional DoS and source code exposure issues.