DEV Community

Cover image for CVE-2025-55182: Meta React Server Components Remote Code Execution Vulnerability
Freedom Coder
Freedom Coder

Posted on • Originally published at scyscan.com

CVE-2025-55182: Meta React Server Components Remote Code Execution Vulnerability

CVE ID

CVE-2025-55182

Vulnerability Name

Meta React Server Components Remote Code Execution Vulnerability

  • Project: Meta
  • Product: React Server Components

Date

  • Date Added: 2025-12-05
  • Due Date: 2025-12-12

Description

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

Known To Be Used in Ransomware Campaigns?

Known

Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Additional Notes

Check for signs of potential compromise on all internet accessible REACT instances after applying mitigations. For more information, please see: https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components ; https://github.com/vercel-labs/fix-react2shell-next?tab=readme-ov-file ; https://nvd.nist.gov/vuln/detail/CVE-2025-55182

More CVEs Info

Common Vulnerabilities & Exposures (CVE) List

Top comments (0)