Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

TaskRay makes onboarding customers fast & efficient with built-in best practices around handoffs from sales to customer onboarding to customer success, powerful insights into onboarding performance & templates to help guide your onboarding projects.

Documents

REPORTSNetwork Diagram
Trust Center Updates

TaskRay Not Impacted by React Server Vulnerabilities

Copy link
General

The security team here at TaskRay became aware of reports concerning critical vulnerabilities disclosed in React Server Components (RSC), including a remote code execution issue tracked as CVE-2025-55182.

Reputable threat intelligence and vendor sources have documented this vulnerability and provided guidance on its impact and mitigation:
https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components
https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components

We want our customers to know that TaskRay is not impacted by this vulnerability.

While TaskRay uses React as part of our front-end technology stack, we do not use React Server Components or React server-side functionality in our product. The disclosed vulnerabilities affect server-side components and runtimes, not client-side React usage.
Since TaskRay’s implementation does not include these server components, the confidentiality, integrity, and availability of our systems remain unharmed.

TaskRay Not Impacted by MOVEit Vulnerabilities

Incidents

Recently, the security team here at TaskRay became aware of the news surrounding a high impact MOVEit vulnerability. Reputable threat intelligence sources have reported that this incident impacts customers of this solution: https://www.securityweek.com/moveit-customers-urged-to-patch-third-critical-vulnerability/.

We want our customers to know that TaskRay is not impacted by this vulnerability.

We do not leverage this technology/software within our product and therefore the confidentiality, integrity, and availability of our systems remain unharmed.

If you think you may have discovered a vulnerability, please send us a note.
Report issue