A very serious vulnerability in React Server Components (RSC) could lead to remote code execution.

The vulnerability, codenamed CVE-2025-55182 , has a CVSS score of 10.0/10. It allows “ unauthenticated remote code executionby exploiting a flaw in the way payloads sent to React Server Function endpoints are decoded ,” the team said in an advisory
“Even if your application does not implement any Server Function endpoints, it may be vulnerable if it supports React Server Components.“.
See also: Microsoft silently fixes Windows LNK error
According to cloud security firm Wiz, the issue is a case of “logical deserialization” resulting from processing RSC payloads in an unsafe manner. As a result, an unauthenticated attacker could craft a malicious HTTP request to any Server Function endpoint that, when deserialized, could execute arbitrary JavaScript code on the server.
The vulnerability affects versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of the following npm packages: react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack.
See also: CISA: Added two Android Framework vulnerabilities to the KEV List

It has been addressed in versions 19.0.1, 19.1.2 and 19.2.1 . New Zealand security researcher Lachlan Davidson is credited with discovering and reporting the bug on November 29, 2025.
Increased risk: Vulnerability affects React and Next.js
It is worth noting that the vulnerability also affects Next.js using App Router. The issue has been assigned the CVE code CVE-2025-66478 (CVSS score: 10.0). It affects versions >=14.3.0-canary.77, >=15 and >=16. The fixed versions are 16.0.7, 15.5.7, 15.4.8, 15.3.6, 15.2.6, 15.1.9 and 15.0.5.
See also: King Addons for Elementor: Critical vulnerability in WordPress plugin
Any library that includes RSC is likely to be affected by the bug, including Vite RSC plugin, Parcel RSC plugin, React Router RSC preview, RedwoodJS, and Waku. Wiz reported that 39% of cloud environments have instances vulnerable to CVE-2025-55182 and/or CVE-2025-66478. Due to the severity of the vulnerability, users are advised to apply the fixes as soon as possible for optimal protection.

“This newly discovered flaw poses a critical threat because it is a master key exploit, which is achieved not by crashing the system, but by abusing trust in the incoming data structures,” Moore said. “The system executes the malicious payload with the same reliability as legitimate code, because it works exactly as intended, but with malicious input.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
