login
quiescence.eu
Skip to content

CVE-2025-55182

Meta React Server Components Remote Code Execution Vulnerability

10.0
CVSS
99.6%
EPSS (exploit prob.)
99.9%
EPSS percentile
Yes
Actively exploited
Yes
Ransomware use
2025-12-05
Added

Summary

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

Affected software

Vendor: Meta  ·  Product: React Server Components

Weakness types (CWE):

CWE-502

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.