How to find Vercel Next.js instances on your network
ID: a1a3ced4-612f-5f53-b172-fd73a0aa305c
STIX ID: report--a1a3ced4-612f-5f53-b172-fd73a0aa305c
Feed Name: runZero Blog
Threat Score
**Critical RCE in React/Next.js (CVE-2025-55182):** A remote, unauthenticated code execution vulnerability in React Server Components (affecting react-server-dom-* packages) impacts Next.js App Router applications. The flaw has a CVSS score of 10.0, is being actively exploited, and multiple Next.js versions are listed as vulnerable; users are advised to update to specified patched versions or downgrade experimental canary releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
