Vulnerabilities/

tRPC has possible prototype pollution in `experimental_nextAppDirCaller`

Severity:
High

Description

Note that this vulnerability is only present when using experimental_caller / experimental_nextAppDirCaller.

Recommendation

Update the @trpc/server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@trpc/server
Anything's wrong? Let us know Last updated on December 16, 2025