HomeSecurityCritical vulnerabilities in React and Next.js allow RCE attacks

Critical vulnerabilities in React and Next.js allow RCE attacks

A very serious vulnerability in React Server Components (RSC) could lead to remote code execution.

React and Next.js

The vulnerability, codenamed CVE-2025-55182 , has a CVSS score of 10.0/10. It allows “ unauthenticated remote code executionby exploiting a flaw in the way payloads sent to React Server Function endpoints are decoded ,” the team said in an advisory

“Even if your application does not implement any Server Function endpoints, it may be vulnerable if it supports React Server Components.“.

See also: Microsoft silently fixes Windows LNK error

According to cloud security firm Wiz, the issue is a case of “logical deserialization” resulting from processing RSC payloads in an unsafe manner. As a result, an unauthenticated attacker could craft a malicious HTTP request to any Server Function endpoint that, when deserialized, could execute arbitrary JavaScript code on the server.

The vulnerability affects versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of the following npm packages: react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack.

See also: CISA: Added two Android Framework vulnerabilities to the KEV List

Critical vulnerabilities in React and Next.js allow RCE attacks

It has been addressed in versions 19.0.1, 19.1.2 and 19.2.1 . New Zealand security researcher Lachlan Davidson is credited with discovering and reporting the bug on November 29, 2025.

Increased risk: Vulnerability affects React and Next.js

It is worth noting that the vulnerability also affects Next.js using App Router. The issue has been assigned the CVE code CVE-2025-66478 (CVSS score: 10.0). It affects versions >=14.3.0-canary.77, >=15 and >=16. The fixed versions are 16.0.7, 15.5.7, 15.4.8, 15.3.6, 15.2.6, 15.1.9 and 15.0.5.

See also: King Addons for Elementor: Critical vulnerability in WordPress plugin

Any library that includes RSC is likely to be affected by the bug, including Vite RSC plugin, Parcel RSC plugin, React Router RSC preview, RedwoodJS, and Waku. Wiz reported that 39% of cloud environments have instances vulnerable to CVE-2025-55182 and/or CVE-2025-66478. Due to the severity of the vulnerability, users are advised to apply the fixes as soon as possible for optimal protection.

Critical vulnerabilities in React and Next.js allow RCE attacks

“This newly discovered flaw poses a critical threat because it is a master key exploit, which is achieved not by crashing the system, but by abusing trust in the incoming data structures,” Moore said. “The system executes the malicious payload with the same reliability as legitimate code, because it works exactly as intended, but with malicious input.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS