Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-55182

Quick assessment

Affected
Meta react-server-dom-webpack
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Meta React Server Components是美国Meta公司的一系列组件。 Meta React Server Components 19.0.0版本、19.1.0版本、19.1.1版本和19.2.0版本存在安全漏洞,该漏洞源于HTTP请求反序列化不当,可能导致远程代码执行。

CVSS 10.0 · Critical KEV · Ransomware EPSS 99.80% · P100

Affected Version Matrix 9

VendorProduct Version RangeStatus
Meta react-server-dom-parcel 19.0.0≤ 19.0.0 affected
19.1.0≤ 19.1.1 affected
19.2.0≤ 19.2.0 affected
Meta react-server-dom-turbopack 19.0.0≤ 19.0.0 affected
19.1.0≤ 19.1.1 affected
19.2.0≤ 19.2.0 affected
Meta react-server-dom-webpack 19.0.0≤ 19.0.0 affected
19.1.0≤ 19.1.1 affected
19.2.0≤ 19.2.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-55182

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Meta React Server Components 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Meta React Server Components是美国Meta公司的一系列组件。 Meta React Server Components 19.0.0版本、19.1.0版本、19.1.1版本和19.2.0版本存在安全漏洞,该漏洞源于HTTP请求反序列化不当,可能导致远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Meta react-server-dom-webpack 19.0.0 ~ 19.0.0 -
Meta react-server-dom-turbopack 19.0.0 ~ 19.0.0 -
Meta react-server-dom-parcel 19.0.0 ~ 19.0.0 -

II. Public POCs for CVE-2025-55182

# POC Description Source Link Shenlong Link
1 React Server Components 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain a remote code execution caused by unsafe deserialization of payloads from HTTP requests to Server Function endpoints, letting unauthenticated attackers execute arbitrary code remotely, exploit requires no authentication. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-55182.yaml POC Details
2 Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server Components (RSC) “Flight” protocol. https://github.com/BankkRoll/Quickcheck-CVE-2025-55182-React-and-CVE-2025-66478-Next.js POC Details
3 CVE-2025-55182 POC https://github.com/ejpir/CVE-2025-55182-research POC Details
4 CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface https://github.com/sickwell/CVE-2025-55182 POC Details
5 A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications https://github.com/fatguru/CVE-2025-55182-scanner POC Details
6 CVE-2025-55182 https://github.com/Ashwesker/Blackash-CVE-2025-55182 POC Details
7 CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface https://github.com/atastycookie/CVE-2025-55182 POC Details
8 None https://github.com/santihabib/CVE-2025-55182-analysis POC Details
9 None https://github.com/xkillbit/cve-2025-55182-scanner POC Details
10 Testing the React Server Components RCE (CVE-2025-55182) https://github.com/rpjboyarski/java4script POC Details
11 React2Shell Proof of Concept https://github.com/whiteov3rflow/CVE-2025-55182-poc POC Details
12 This POC demonstrates CVE-2025-55182 using actual `react-server-dom-webpack@19.0.0` vulnerable code. https://github.com/Pa2sw0rd/exploit-CVE-2025-55182-poc POC Details
13 CVE-2025-55182 https://github.com/kk12-30/CVE-2025-55182 POC Details
14 For CVE-2025-55182 and CVE-2025-66478 Security Response https://github.com/heiheishushu/rsc_detect_CVE-2025-55182 POC Details
15 CVE-2025-55182 漏洞利用GUI,PoC / Exploit for CVE-2025-55182 & CVE-2025-66478 https://github.com/songsanggggg/CVE-2025-55182 POC Details
16 检测针对 CVE-2025-55182(React 服务器组件远程代码执行漏洞)的扫描器 https://github.com/M0onPu15e/next.js-scanner POC Details
17 a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test and understand the vulnerability. https://github.com/ThemeHackers/CVE-2025-55182 POC Details
18 a realistic POC demonstrating the missing `hasOwnProperty` check in react-server-dom-webpack@19.0.0 https://github.com/joshterrill/CVE-2025-55182-realistic-poc POC Details
19 A Comprehensive CVE-2025-55182 Detection and Security Assessment Tool https://github.com/mingyisecurity-lab/CVE-2025-55182-TOOLS POC Details
20 High-performance exploitation engine for CVE-2025-55182 (React Server Components RCE) https://github.com/joaonevess/rust-flight POC Details
21 Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components. Scan npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Auto-fix, SARIF output, GitHub Actions, Vercel integration, and runtime protection middleware. https://github.com/gensecaihq/react2shell-scanner POC Details
22 None https://github.com/sudo-Yangziran/CVE-2025-55182POC POC Details
23 一款针对 CVE-2025-55182 的独立安全评估工具,基于 Go 开发,提供图形化界面(GUI),用于快速完成漏洞检测与验证。 https://github.com/Rsatan/CVE-2025-55182-Tools POC Details
24 High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) https://github.com/assetnote/react2shell-scanner POC Details
25 RCE Auto exploit for CVE-2025-55182 https://github.com/jf0x3a/CVE-2025-55182-exploit POC Details
26 React/Next.js RCE CVE-2025-55182 checker https://github.com/aspen-labs/CVE-2025-55182-checker POC Details
27 None https://github.com/dissy123/cve-2025-55182 POC Details
28 Pre-auth RCE in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. https://github.com/dwisiswant0/CVE-2025-55182 POC Details
29 See if your endpoint could be vulnerable. https://github.com/Chelsea486MHz/CVE-2025-55182-test POC Details
30 None https://github.com/oways/React2shell-CVE-2025-55182-checker POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-55182

请登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-55182

Anonymous User
2026-01-15 06:09:46

Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.


Leave a comment