CVE-2025-55182
Description
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
In plain language
AI Act nowCVE-2025-55182 is a serious bug in certain React Server Components releases where an attacker can run code on your server over the network without signing in—most small businesses using affected versions should act now.
CVE-2025-55182 is a pre-authentication remote code execution in React Server Components (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) caused by unsafe deserialization of payloads received via HTTP requests to Server Function endpoints; it is listed in CISA KEV and was used in ransomware campaigns.
What to do now
- Check whether your stack uses React Server Components and whether any of these packages are on versions 19.0.0, 19.1.0, 19.1.1, or 19.2.0: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack (and/or Next.js with these components).
- If you are on an affected version, upgrade React Server Components to the fixed releases: react-server-dom-parcel / react-server-dom-turbopack / react-server-dom-webpack fixed in 19.0.1 (or 19.1.2 / 19.2.1 as applicable).
- After upgrading, verify your “Server Function endpoints” are no longer exposing unsafe deserialization behavior (re-test any custom endpoints that process Server Function payloads).
- If you cannot upgrade immediately, follow the vendor’s mitigation guidance from the React security blog and apply any recommended compensating controls until you can patch.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Малварь ChocoPoC распространяется под видом фальшивых эксплоитовru-ru·Хакер (xakep.ru)· PoC malware
- No Manners Here: The Ruthless Rise of The Gentlemen Ransomwareen-us·Palo Alto Unit 42· Exploited The Gentlemen ransomware
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Reposen·The Hacker News· PoC malware
- New ChocoPoC malware targets researchers via trojanized PoC exploitsen-us·BleepingComputer· PoC ChocoPoC malware
- ChocoPoc malware delivered via trojanized exploits on GitHuben-us·BleepingComputer· PoC ChocoPoC malware
- New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacksen·The Hacker News· PoC Microsoft SharePoint malware
- StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoaderen-us·Kaspersky Securelist· Research SharkLoader malware
- Как и чем ломали российские компании. Исследование Jet CSIRTru·Хабр — Информационная безопасность· Research Jet CSIRT ransomware
- What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security anden-us·Kaspersky Securelist· Research Kaspersky Container Security rce
- AI Threat Landscape Digest March-April 2026en-us·Check Point Research· Exploited Claude Code ai-ml
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-55182 and every CVE in our database. Create a free account — no credit card required.
Create Free Account