Critical React and Next.js Enables Remote Attackers to Execute Malicious Code
ID: 6d49e379-e5d8-56d4-ad5b-8ddbb35ca4c1
STIX ID: report--6d49e379-e5d8-56d4-ad5b-8ddbb35ca4c1
Feed Name: cybersecurityNews.com
A critical unauthenticated RCE vulnerability affects React Server Components and Next.js (CVE-2025-55182, CVE-2025-66478) due to insecure deserialization of the RSC "Flight" payload; affected versions include react-server-dom-* 19.0.0–19.2.0 and Next.js 14.3.0-canary, 15.x, 16.x (CVSS 10.0). The issue is exploitable via a crafted HTTP request against default deployments, testing shows high reliability, and vendors have released patches—organisations are urged to urgently upgrade RSC-enabled dependencies and treat exposed deployments as high-risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
