logo

React/Next.js CVE-2025-55182 Vulnerability Analysis

ID: 85e3b318-b6bf-532d-a721-7bcf6ad42097

STIX ID: report--85e3b318-b6bf-532d-a721-7bcf6ad42097

Feed Name: CertiK Blog

Threat Score
90/100

Date Published: 2025-12-06

Date Updated: 2026-06-11

...
...

A critical Remote Code Execution vulnerability (CVE-2025-55182, CVSS 10.0) affecting React/Next.js was disclosed and is present in many Web3 applications; exploit consequences include server compromise, sensitive data or private key exfiltration, and injected JavaScript wallet drainers. The advisory lists vulnerable Next.js and React versions, provides quick self-checks (window.next.version and npm ls react), and gives remediation and follow-up steps (upgrade to patched versions, verify lockfiles/node_modules, rebuild/deploy, rotate secrets, review logs); additional CVEs affecting React Server Components (DoS and source-code exposure) were later disclosed, and immediate upgrades are strongly recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.