CVE-2025-55182
⚡ CISA KEV🔐 RansomwarePublished: —Modified: —Vendor: MetaProduct: React Server Components
—
CVSS v3
99.6%
EPSS
⚡ Added to KEV on 2025-12-05 · Federal agencies must remediate by 2025-12-12
Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.
💣 Public Exploits1
From Exploit-DB
| React Server 19.2.0 - Remote Code Execution | multiple | webapps | 2026-04-09 |
🔍 Sigma Detection Rules2
Rules tagged with this CVE
| high | Linux Suspicious Child Process from Node.js - React2Shell | linux | — |
| high | Windows Suspicious Child Process from Node.js - React2Shell | windows | — |
🛠️ Patch Details20
Affected/fixed versions from threat intel reports
| React2Shell | source ↗ | ||
| React Server Components | — | — | source ↗ |
| OpenClaw | — | — | source ↗ |
| Recorded Future Attack Surface Intelligence | — | — | source ↗ |
| Meta React | React < 19.0.1; Next.js multiple lines | source ↗ | |
| Next.js | — | — | source ↗ |
| React | 19.1.0 | source ↗ | |
| Next.js | 15.4.6 | source ↗ | |
| Baota Baota (BT) management panel | source ↗ | ||
| NGINX | source ↗ | ||
| Google Chrome | — | — | source ↗ |
| React | source ↗ | ||
| React Server Components (react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack) | version 19.0, 19.1.0, 19.1.1, and 19.2.0 | versions 19.0.1, 19.1.2, and 19.2.1 | source ↗ |
| Vercel Next.js | — | — | source ↗ |
| Parcel Parcel RSC | — | — | source ↗ |
| Vite Vite RSC plugin | — | — | source ↗ |
| React Router React Router (unstable RSC APIs) | — | — | source ↗ |
| Vercel Next.js | — | — | source ↗ |
| React react-server-dom-turbopack | 19.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1 | source ↗ |
| React react-server-dom-parcel | 19.0, 19.1.0, 19.1.1, 19.2.0 | 19.0.1, 19.1.2, 19.2.1 | source ↗ |
📰 Threat Intel Coverage20
Digest reports mentioning this CVE
📎 References0
No reference URLs.