/Vulnerability Library

React Server Components - Remote Code Execution

CVE-2025-55182
Verified

Description

React Server Components 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain a remote code execution caused by unsafe deserialization of payloads from HTTP requests to Server Function endpoints, letting unauthenticated attackers execute arbitrary code remotely, exploit requires no authentication.

Severity

Critical

CVSS Score

10

Exploit Probability

100%

Published Date

December 4, 2025

Template Author

dhiyaneshdk, princechaddha, assetnote
+3

CVE-2025-55182.yaml
10.0Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2025-55182
CWE ID:
cwe-502

References

https://github.com/assetnote/react2shell-scannerhttps://gist.github.com/maple3142/48bc9393f45e068cf8c90ab865c0f5f3https://www.facebook.com/security/advisories/cve-2025-55182http://www.openwall.com/lists/oss-security/2025/12/03/4https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-componentshttps://github.com/vercel/next.js/security/advisories/GHSA-9qr9-h5gf-34mphttps://vercel.com/changelog/cve-2025-55182https://github.com/Chocapikk/CVE-2025-55182

Remediation Steps

Update to the latest version that fixes the unsafe deserialization issue.