logo

A Vulnerability in React Server Component (RSC) Could Allow for Remote Code Execution

ID: 4c24820e-25ec-54b9-827c-2fe76a8f7251

STIX ID: report--4c24820e-25ec-54b9-827c-2fe76a8f7251

Feed Name: CISecurity.org Advisories

Threat Score
85/100

Date Published: 2025-12-05

Date Updated: 2026-04-27

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2025-55182) has been disclosed in React Server Components (RSC) Flight protocol. Unsafe deserialization of attacker-controlled serialized Flight data in RSC request/response handling allows a remote attacker to send a specially crafted HTTP request that deserializes arbitrary objects and enables code execution; no authentication, session, or user interaction is required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.