vulnti.work

Meta React Server Components Remote Code Execution Vulnerability

Critical CVSS 10.0 Listed in CISA KEV
CVECVE-2025-55182
First seen2025-12-05 00:00 UTC
Disclosed2025-12-03 16:15 UTC
Last updated2026-09-02 07:15 UTC
Channel statuspending_review

Summary

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Meta:React Server Components
  • :
  • :

Sources

  • CISA KEV DATABASE
  • NVD DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV
  3. nvd_ingest NVD