vulnti.work

Meta React Server Components Remote Code Execution Vulnerability

Critical Listed in CISA KEV
CVECVE-2025-55182
First seen2025-12-05 00:00 UTC
Disclosed2025-12-05 00:00 UTC
Last updated2026-07-14 20:15 UTC
Channel statuspending_review

Summary

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Meta:React Server Components

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV