Skip to content
Saturday, December 6, 2025
Critical Published: Dec 03, 2025 Modified: Dec 06, 2025

CVE-2025-55182

10 CVSS SCORE
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Share:

Description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

CVSS Vector Details

Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Changed
Confidentiality High
Integrity High
Availability High

Affected Software Configurations

  • a facebook react 19.0.0 * * * * * * *
  • a facebook react 19.1.0 * * * * * * *
  • a facebook react 19.1.1 * * * * * * *
  • a facebook react 19.2.0 * * * * * * *
  • a vercel next.js * * * * * node.js * *
  • a vercel next.js 14.3.0 canary77 * * * node.js * *
  • a vercel next.js 14.3.0 canary78 * * * node.js * *
  • a vercel next.js 14.3.0 canary79 * * * node.js * *
  • a vercel next.js 14.3.0 canary80 * * * node.js * *
  • a vercel next.js 14.3.0 canary81 * * * node.js * *

Weaknesses (CWE)

  • CWE-502