Critical React Flaw Triggers Calls for Immediate Action
ID: c62076b1-e3ba-5b0c-a7c4-50ca1cbc1212
STIX ID: report--c62076b1-e3ba-5b0c-a7c4-50ca1cbc1212
Feed Name: Dark Reading
React Server Components and downstream Next.js have two critical RCE vulnerabilities (CVE-2025-55182 and CVE-2025-66478) with CVSS 10, enabling unauthenticated remote code execution via unsafe deserialization. A public proof-of-concept is available and Amazon reported exploitation by China-nexus groups (e.g., Earth Lamia, Jackpot Panda) within hours of disclosure; vendors and cloud providers have issued mitigations and version updates and organizations are strongly urged to patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
