Skip to main content
CISA Known Exploited Vulnerabilities

Meta React Server Components Remote Code Execution Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2025-12-05
Remediation due
2025-12-12
Ransomware
Known use

Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA notes
Check for signs of potential compromise on all internet accessible REACT instances after applying mitigations. For more information, please see: https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components ; https://github.com/vercel-labs/fix-react2shell-next?tab=readme-ov-file ; https://nvd.nist.gov/vuln/detail/CVE-2025-55182

Description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Severity

CVSS 3.1 · CNA10 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impacttotal

Affected Products

VendorProductAffected versions
Metareact-server-dom-webpack
19.0.0 to 19.0.0
19.1.0 to 19.1.1
19.2.0 to 19.2.0
Metareact-server-dom-turbopack
19.0.0 to 19.0.0
19.1.0 to 19.1.1
19.2.0 to 19.2.0
Metareact-server-dom-parcel
19.0.0 to 19.0.0
19.1.0 to 19.1.1
19.2.0 to 19.2.0

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.