React Server Components - Remote Code Execution
CVE-2025-55182
Verified
Description
React Server Components 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain a remote code execution caused by unsafe deserialization of payloads from HTTP requests to Server Function endpoints, letting unauthenticated attackers execute arbitrary code remotely, exploit requires no authentication.
Severity
Critical
CVSS Score
10
Exploit Probability
100%
Published Date
December 4, 2025
Template Author
dhiyaneshdk, princechaddha, assetnote
+3
CVE-2025-55182.yaml
10.0Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2025-55182
CWE ID:
cwe-502
References
https://github.com/assetnote/react2shell-scannerhttps://gist.github.com/maple3142/48bc9393f45e068cf8c90ab865c0f5f3https://www.facebook.com/security/advisories/cve-2025-55182http://www.openwall.com/lists/oss-security/2025/12/03/4https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-componentshttps://github.com/vercel/next.js/security/advisories/GHSA-9qr9-h5gf-34mphttps://vercel.com/changelog/cve-2025-55182https://github.com/Chocapikk/CVE-2025-55182
Remediation Steps
Update to the latest version that fixes the unsafe deserialization issue.