CVE-2025-55182

Published Dec 3, 2025

Last updated a month ago

Exploit knownCVSS critical 10.0
npm
React
react2shell
Supply chain
Business logic
Cloud
Zero-day
ICS
Network
Port (443)
Server
AWS
OT

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-55182 is a critical unauthenticated remote code execution (RCE) vulnerability found in React Server Components (RSC) versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. This vulnerability affects packages including `react-server-dom-parcel`, `react-server-dom-turbopack`, and `react-server-dom-webpack`. The flaw stems from insecure deserialization in the RSC payload handling logic, allowing attacker-controlled data to influence server-side execution. Exploitation requires only a crafted HTTP request. Patches are available for React and Next.js. It is recommended to upgrade to patched React versions such as 19.0.1, 19.1.2, or 19.2.1, and to update frameworks like Next.js to their corresponding patched versions.

Description
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Source
cve-assign@fb.com
NVD status
Analyzed
Products
react, next.js

Insights

Analysis from the Intruder Security Team
Published Dec 4, 2025 Updated Dec 9, 2025

This vulnerability allows for code execution via a deserialisation vulnerability within the react-server-dom packages. This will affect React, NextJS and downstream projects who utilise these frameworks.

AssetNote released a technical research post and detection technique which is effective at identifying unpatches instances, where as full RCE chains may fail due to WAF's fingerprinting those payloads and bypasses heavily. Vercel's CEO released a simple breakdown of the issue and how it works.

We have witnessed widespread exploitation activity for this vulnerability, especially exploiting this to deploy an in-memory webshell. There has been some community efforts to detect exploitation activity, however exploiting this vulnerability usually leaves little to no trace which is difficult for defenders.

Patching immediately is the only effective strategy for dealing with this vulnerability.

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Meta React Server Components Remote Code Execution Vulnerability
Exploit added on
Dec 5, 2025
Exploit action due
Dec 12, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-502

Social media

Hype score
Not currently trending
  1. React Server Components Remote Code Execution (CVE-2025-55182) Now Has Public Exploit Code, Patch Immediately https://t.co/oHFKCAXVU6 #cybersecurity #threatintelligence https://t.co/VLoMlMrbzc

    @cybr_monk

    11 Sept 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Hack The Box Reactor machine fully compromised via unauthenticated RCE in CVE-2025-55182 (React2Shell) affecting outdated Next.js. Attack chain includes Nmap discovery, public exploit for initial shell as node, hash extraction from reactor.db, offline cracking for SSH access,

    @WorldCyberNewsX

    11 Sept 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Most AI tools hallucinate CVEs and give broken exploits.I asked Luah AI to research React2Shell (CVE-2025-55182) and generate a working https://t.co/y14Vc8q12E returned a full Python exploit for the critical pre-auth RCE in React/Next.js. https://t.co/dHHnE9GUmt

    @luahai_com

    10 Sept 2026

    24 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Spawned & rooted Reactor on HTB tonight. React2Shell (CVE-2025-55182) → unauth RCE in a Next.js dashboard. MD5 from the app DB → engineer's SSH pass. Root = a root node --inspect on loopback, driven over the DevTools protocol. https://t.co/TxeqLo408f #HackTheBox #HTB

    @_SP1R4

    9 Sept 2026

    45 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Spawned & rooted Reactor on HTB tonight. React2Shell (CVE-2025-55182) → unauth RCE in a Next.js dashboard. MD5 from the app DB → engineer's SSH pass. Root = a root node --inspect on loopback via the DevTools protocol. https://t.co/TxeqLo408f #HackTheBox #HTB #InfoSec #P

    @_SP1R4

    9 Sept 2026

    44 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2024-3094 CVE-2025-31324 CVE-2025-55182 CVE-2025-57819 CVE-2026-28576 ..🧵👇

    @exploitgrid

    8 Sept 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. This week's KEV additions: CVE-2021-44228 (Apache), CVE-2026-10520 (Ivanti), CVE-2025-32432 (Craft CMS), CVE-2020-0796 (Microsoft), CVE-2025-55182 (Meta). All are actively exploited. Prioritize based on your asset inventory, not just CVSS 10.0 scores.

    @BytesNora

    7 Sept 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2026-46339 CVE-2024-45798 CVE-2025-55182 CVE-2025-57819 CVE-2025-59528 ..🧵👇

    @exploitgrid

    29 Aug 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. I DID IT AGAIN RCE LEAD TO ADMIN PAYMENT PORTAL🔥🔥🔥 Next.js will you marry me ❤️❤️ ❤️ Tips: I found the embedded link in the js which i input which turn on Notifications it’s Vulnerable to RCE Next.js RSC Exploit Tool (CVE-2025-55182) https://t.co/epDh4

    @Shabosec

    27 Aug 2026

    9053 Impressions

    12 Retweets

    124 Likes

    102 Bookmarks

    6 Replies

    2 Quotes

  10. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: #CVE-2025-55182 CVE-2026-2796 CVE-2026-2768 CVE-2026-34910 CVE-2026-34909 CVE-2026-58231 CVE-2026-48907 ..🧵👇

    @exploitgrid

    25 Aug 2026

    121 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Look at what I saw today. React 18.3.1 frontend looks fine, but if you're using React Server Components, React2Shell (CVE-2025-55182) gives unauthenticated CVSS 10.0 RCE via the Flight protocol. Update server-side packages like react-server-dom-webpack NOW. 💀 @RedHatPenteste

    @focus_furry

    22 Aug 2026

    390 Impressions

    0 Retweets

    9 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  12. Huge spike in React2Shell (CVE-2025-55182) exploitation activity over the past couple of days. https://t.co/GaRTW5EfOP

    @kev_intel

    22 Aug 2026

    116 Impressions

    2 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-EDB-AWZes1i ( CVE-2026-48907 ) EGE-GH-86PDTBb ( CVE-2025-55182 ) EGE-GH-uET14Zz ( CVE-2026-20079 ) EGE-GH-voHgFaT ( CVE-2026-59310 ) EGE-GH-seDlYMs ( CVE-2026-59310 ) ..🧵👇

    @exploitgrid

    18 Aug 2026

    88 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-z2Wb7PG ( CVE-2026-72898 ) EGE-GH-UkSJfvx ( CVE-2026-73678 ) EGE-GH-MKUk78n ( CVE-2023-22621 ) EGE-GH-EjpQM0Q ( CVE-2025-3243, CVE-2025-32433 ) EGE-GH-seDm3r2 ( CVE-2025-55182 ) ..🧵👇

    @exploitgrid

    17 Aug 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. A deserialization bug in Meta's React Server Components gives you pre-authentication RCE. We reproduced the public vulnerability, CVE-2025-55182, end-to-end. Cost to build the exploit and verify the fix was $2.96.

    @vulnresearchlab

    12 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 2026年Q2の攻撃検知レポートを公開📊 1日873万回・1秒101回のペースで検知。イタリア発信元とみられる攻撃が前年比75倍に急増していて追いかけがいがあります🔥 React2Shell(CVE-2025-55182)の悪用動向も要チェック

    @csc_engineer

    7 Aug 2026

    88 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. A maximum-severity security flaw has been disclosed in React Server Components (RSC) that, if successfully exploited, could result in remote code execution. The vulnerability, tracked as CVE-2025-55182, carries a CVSS s... https://t.co/FnxWgnlc5C

    @pedri77

    2 Aug 2026

    149 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  18. Next.js/ReactのApp RouterにRCE(CVE-2025-55182)がCVSS9.8で公開。React 19系+Next.js 15/16系が対象で、細工したリクエストからサーバ側で任意コード実行に至りうる。自前SSRを本番で回しているなら要確認。

    @tsumikasanedev

    31 Jul 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  19. Pro pack 1.70 summer release: - React Server RCE CVE-2025-55182 - Tekla Web Viewer Remote File Create Vulnerability - WordPress Madara CVE-2025-4524 - Serva WEB Server Vulnerability - HomeSeer Password Decrypt

    @ExCraft_labs

    26 Jul 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Top KEVs hitting KEVIntel sensors this week: 1. CVE-2021-41773 - 732 2. CVE-2022-47945 - 466 3. CVE-2025-55182 - 337 4. CVE-2026-0770 - 178 5. CVE-2026-63030 - 113 2,497 exploitation attempts from 500 source IPs across our sensors. Patch what attackers are actually exploiting.

    @kev_intel

    23 Jul 2026

    74 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  21. Cytellite recent detection targeting CVE-2025-55182 — Storm Industries LLC Visit -- https://t.co/YQH2PpvPFR #Loginsoft #Cytellite #Cybersecurity #CVE202555182 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/v4pVuVfl74

    @Loginsoft_Intel

    22 Jul 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🚨 CVE-2025-55182: Critical 10.0 CVSS React Server Components Pre-Auth RCE https://t.co/Ctx79sIUe8 #Cybersecurity #Infosec #AppSec #RCE #React #NextJS #React2Shell #CVE202555182 #PoC #EthicalHacking #BugBounty #PatchNow https://t.co/ouBX3okUGd

    @r0otk3r

    12 Jul 2026

    38 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Hey, world 🤙 I just released a few projects on GitHub: - Two PoCs for #CVE-2022-22965 and #CVE-2025-55182, written in C and Go. - A simple C# project demonstrating how AES encryption works. GitHub: https://t.co/uS2tdeNxeq More CVE exploit are coming, stay tuned Peace, ✌

    @RootEvil333

    8 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. CVE-2025-55182: Consolidated Exploitation of React Server Components Is Concerning but Not Catastrophic https://t.co/D5l5KNHi9j #CyberSecurity #DataBreach #Vulnerability

    @cyber_newsroom

    5 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. CVE-2025-55182 Exploitation Reveals Process Failures in React Server Components Security https://t.co/cXVbudZXGr #CVE2025 #ReactJS #CyberSecurity

    @cyber_newsroom

    5 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. CVE-2025-55182: React Server Components Under Siege While We Sleep https://t.co/DDNhtCMSbE #CVE2025 #ReactJS #ServerComponents

    @cyber_newsroom

    5 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. CVE-2025-55182: Consolidated Exploitation of React Server Components Signals Looming Danger https://t.co/2nkEfOrpyx #CVE2025 #CyberSecurity #DataProtection

    @cyber_newsroom

    5 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. CVE-2025-55182: React Server Components Under Persistent Attack https://t.co/jYHWOC1DzF #CVE2025 #React #CyberSecurity

    @cyber_newsroom

    5 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Vect RaaS and TeamPCP formalize a supply chain-to-ransomware pipeline: credential theft across open-source tooling feeds industrialized extortion across 1,000+ SaaS environments. Key details: - TeamPCP (also known as PCPcat, ShellForce, DeadCatx3) exploited CVE-2025-55182 (CVSS

    @DFIR_Radar

    2 Jul 2026

    212 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  30. CVE-2025-55182 (React2Shell) is a pre-auth RCE in React Server Components. CVSS 10, still exploited in the wild. A malformed RSC payload deserializes straight into code execution. Confirm the version you actually ship is on a patched release, not just whatever latest was.

    @4Ndr3w10000

    30 Jun 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. React ist battle-tested. Und trotzdem reicht ein tiefer Blick für eine ziemlich wilde RCE-Story. Der React2Shell-Artikel von Lachlan Davidson ist starke Security-Lektüre. Aus Protokoll-Neugier plötzlich CVE-2025-55182 wird. https://t.co/p5XVxb1ZgR https://t.co/ZwToWRauCC

    @EngKiosk

    29 Jun 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. TRC analysis shows attackers exploited React2Shell (CVE-2025-55182) within hours of disclosure to deploy cryptominers and establish persistent C2 channels. State-sponsored groups used tunneling tools like MINOCAT across compromised React Server Components. Runtime segmentation

    @aviatrixtrc

    22 Jun 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) - Amazon Web Services #CISO https://t.co/MBIIz5PGiA

    @compuchris

    19 Jun 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. #threatreport #MediumCompleteness Analysis of the APT-C-26 (Lazarus) group's attack operations using CVE-2025-55182 with Copperhedge components | 03-06-2026 Source: https://t.co/EDGdTC2Hmx Key details below ↓ 🧑‍💻Actors/Campaigns: Lazarus (🧠motivation: information_th

    @rst_cloud

    4 Jun 2026

    138 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  35. "APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析" published by Qihoo360. #APT-C-26, #CVE-2025-55182, #Copperhedge, #DPRK, #CTI

    @lazarusholic

    4 Jun 2026

    377 Impressions

    4 Retweets

    8 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  36. 360 Advanced Threat Research Institute states Lazarus used CVE-2025-55182 with Copperhedge Loader and MultiRelay/UAC bypass to breach financial and blockchain targets, enabling persistence, data theft, and C2 communications. https://t.co/0zYiy5JI0u

    @Cyber_O51NT

    4 Jun 2026

    494 Impressions

    1 Retweet

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  37. Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component -- https://t.co/a1D6B4Q49y

    @AndreGironda

    3 Jun 2026

    61 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Analysis of #Lazarus Campaign Exploiting CVE-2025-55182 and Copperhedge Malware This report analyzes an ongoing intrusion campaign launched by the notorious Lazarus Group, leveraging the high-risk unauthenticated remote code execution (RCE) vulnerability CVE-2025-55182 paired htt

    @blackorbird

    3 Jun 2026

    2196 Impressions

    13 Retweets

    31 Likes

    17 Bookmarks

    0 Replies

    0 Quotes

  39. GitHub - Jenderal92/CVE-2025-55182-React2shell: CVE-2025-55182 Exploit Tool – Python 2.7 exploit for Next.js prototype pollution leading to RCE · GitHub https://t.co/t2ytOU3xNn

    @akaclandestine

    1 Jun 2026

    1576 Impressions

    3 Retweets

    11 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  40. Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2026-5194 3 - CVE-2026-48095 4 - CVE-2026-23652 5 - CVE-2026-45585 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    29 May 2026

    97 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  41. First machine of @hackthebox_eu 𝗦𝗲𝗮𝘀𝗼𝗻 𝟭𝟭 down. 🔥 Rooted 𝗥𝗲𝗮𝗰𝘁𝗼𝗿 through: CVE-2025-55182 𝗥𝗖𝗘 → SQLite creds → cracked MD5 → Node.js debugger → root Solid box with a real-world vuln chain. Great start to the season

    @sakibulalikhan

    25 May 2026

    210 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  42. React 19 / Next.js 15 のパッチ脆弱性 (CVE-2025-55182 / 55183 / 55184) を手動追跡で素早く対応した話 https://t.co/qnRL6PxeYn #Qiita

    @yousukezan

    25 May 2026

    1122 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2016-5195 3 - CVE-2026-20223 4 - CVE-2026-41940 5 - CVE-2026-41089 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    23 May 2026

    322 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. We identified a large-scale React2Shell (CVE-2025-55182) operation that scanned millions of targets and confirmed 900+ successful exploits. Logs showed an automated pipeline for exploitation, hit scoring, alerting, and secret harvesting. Claude Code and OpenClaw were used as an h

    @TheDFIRReport

    22 May 2026

    5598 Impressions

    20 Retweets

    50 Likes

    32 Bookmarks

    2 Replies

    0 Quotes

  45. use server" isn't a label. It's an exposed endpoint. CVE-2025-55182 proved React Server Components created an implicit RPC layer — no schemas, no explicit contracts. Just vibes and hope. Update your deps. Then actually read what you're exposing. #nextjs #security

    @KumbajiK

    20 May 2026

    304 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  46. CVE-2025-55182 demonstrates, once more, the danger of unsafe deserialization and input validation. Our comprehensive write-up for the React2Shell vulnerability is here. 👉 Check it out: https://t.co/t4SMtQadDh #appsec #securecoding #programming https://t.co/zuigwxdFcb

    @secdim

    19 May 2026

    329 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. Post this: 🚨 Critical heads-up for Next.js App Router / React Server Components apps: CVE-2025-55182 is a CVSS 10 pre-auth RCE in React Server Components. Upgrade immediately to patched Next.js/React RSC versions and rotate secrets if your app was exposed while unpatched.

    @ryancarson

    15 May 2026

    1085 Impressions

    1 Retweet

    8 Likes

    5 Bookmarks

    12 Replies

    0 Quotes

  48. Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware https://t.co/b4adaWC6ih The article details a sophisticated cyber intrusion involving the EtherRAT malware family, which initially targeted Linux servers via CVE-2025-55182 and later ex… https://t.co/2p26i4AH3

    @f1tym1

    13 May 2026

    216 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. 😃ช่องโหว่ความปลอดภัยระดับวิกฤต (2025-2026): พบช่องโหว่ CVE-2025-55182 ที่มีคะแนนความรุนแรงสูงสุด (10/10) ใน React 19 และ Next.js ที

    @natty_z2234

    13 May 2026

    226 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 😃ช่องโหว่ความปลอดภัยระดับวิกฤต (2025-2026): พบช่องโหว่ CVE-2025-55182 ที่มีคะแนนความรุนแรงสูงสุด (10/10) ใน React 19 และ Next.js ที

    @natty_z2234

    13 May 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations