CVE-2025-55182: React Server Components are Vulnerable to RCE
(updated )
There is an unauthenticated remote code execution vulnerability in React Server Components.
We recommend upgrading immediately.
The vulnerability is present in versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 of:
References
- github.com/advisories/GHSA-fv66-9v8q-g76r
- github.com/ejpir/CVE-2025-55182-poc
- github.com/facebook/react
- github.com/facebook/react/commit/7dc903cd29dac55efb4424853fd0442fef3a8700
- github.com/facebook/react/pull/35277
- github.com/facebook/react/releases/tag/v19.0.1
- github.com/facebook/react/releases/tag/v19.1.2
- github.com/facebook/react/releases/tag/v19.2.1
- github.com/facebook/react/security/advisories/GHSA-fv66-9v8q-g76r
- news.ycombinator.com/item?id=46136026
- nvd.nist.gov/vuln/detail/CVE-2025-55182
- react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components
- www.facebook.com/security/advisories/cve-2025-55182
Code Behaviors & Features
Detect and mitigate CVE-2025-55182 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →