A Vulnerability in React Server Component (RSC) Could Allow for Remote Code Execution
ID: 4c24820e-25ec-54b9-827c-2fe76a8f7251
STIX ID: report--4c24820e-25ec-54b9-827c-2fe76a8f7251
Feed Name: CISecurity.org Advisories
Threat Score
A critical unauthenticated remote code execution vulnerability (CVE-2025-55182) has been disclosed in React Server Components (RSC) Flight protocol. Unsafe deserialization of attacker-controlled serialized Flight data in RSC request/response handling allows a remote attacker to send a specially crafted HTTP request that deserializes arbitrary objects and enables code execution; no authentication, session, or user interaction is required.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
