logo

Critical React and Next.js Enables Remote Attackers to Execute Malicious Code

ID: 6d49e379-e5d8-56d4-ad5b-8ddbb35ca4c1

STIX ID: report--6d49e379-e5d8-56d4-ad5b-8ddbb35ca4c1

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical unauthenticated RCE vulnerability affects React Server Components and Next.js (CVE-2025-55182, CVE-2025-66478) due to insecure deserialization of the RSC "Flight" payload; affected versions include react-server-dom-* 19.0.0–19.2.0 and Next.js 14.3.0-canary, 15.x, 16.x (CVSS 10.0). The issue is exploitable via a crafted HTTP request against default deployments, testing shows high reliability, and vendors have released patches—organisations are urged to urgently upgrade RSC-enabled dependencies and treat exposed deployments as high-risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.