CVE-2025-55182: Critical React Exploit Hits Millions of Sites
ID: 0ada90f5-6e34-5e6c-ac51-f22d5a2f6bc1
STIX ID: report--0ada90f5-6e34-5e6c-ac51-f22d5a2f6bc1
Feed Name: HackerOne Blog
Threat Score
CVE-2025-55182 is a critical (CVSS 10.0) unauthenticated RCE in React Server Components and affected Next.js releases that could impact millions of sites; the report describes affected versions, active exploitation by threat actors (including nation-state-linked groups), indicators of compromise (HTTP headers, payload patterns, host behaviors), remediation steps (patching and audits), and observed attacker infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
