InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: Critical RSC bug in React and Next.js allows unauthenticated remote code execution
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > Critical RSC bug in React and Next.js allows unauthenticated remote code execution
Technology

Critical RSC bug in React and Next.js allows unauthenticated remote code execution

December 3, 2025 2 Min Read
Share
Critical RSC bug in React and Next.js allows unauthenticated remote code execution
SHARE

A maximum severity security flaw has been disclosed in React Server Components (RSC) that could allow remote code execution if successfully exploited.

This vulnerability is tracked as CVE-2025-55182 and has a CVSS score of 10.0.

The React team said in an alert issued today that this allows for “unauthenticated remote code execution by exploiting a flaw in the way React decodes payloads sent to React server function endpoints.”

“Even if your app doesn’t implement the React Server Function endpoint, it may still be vulnerable if it supports React Server components.”

According to cloud security company Wiz, the issue is a case of logical deserialization caused by processing the RSC payload in an insecure manner. As a result, an unauthenticated attacker could make a malicious HTTP request to any server function endpoint and, once deserialized by React, could execute arbitrary JavaScript code on the server.

This vulnerability affects versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of the following npm packages:

  • react-server-dom-webpack
  • react server dumb parcel
  • react server dumb turbo pack

This issue is addressed in versions 19.0.1, 19.1.2, and 19.2.1. New Zealand-based security researcher Lachlan Davidson is credited with discovering and reporting the flaw on November 29, 2025.

Note that this vulnerability also affects Next.js that uses App Router. This issue has been assigned CVE identifier CVE-2025-66478 (CVSS score: 10.0). Affects versions 14.3.0-canary.77 and above, 15 and above, and 16 and above. Patched versions are 16.0.7, 15.5.7, 15.4.8, 15.3.6, 15.2.6, 15.1.9, and 15.0.5.

However, any library that bundles RSC may be affected by this flaw. This includes, but is not limited to, Vite RSC plugin, Parcel RSC plugin, React Router RSC preview, RedwoodJS, and Waku.

See also  Samsung fixes critical zero-day CVE-2025-21043 utilized in Android attacks

Wiz said that 39% of cloud environments have instances vulnerable to CVE-2025-55182 and CVE-2025-66478. Given the severity of the vulnerability, we recommend that users apply the fix as soon as possible for optimal protection.

Share This Article
Twitter Copy Link
Previous Article Destiny 2 Renegades has had a huge surge on Steam, but even Star Wars mania can't recapture the highs of my favorite FPS Destiny 2 Renegades has had a huge surge on Steam, but even Star Wars mania can’t recapture the highs of my favorite FPS
Next Article Trump's approval rating plummets due to economic crisis Trump’s approval rating plummets due to economic crisis

Latest News

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

threat actor known as silver fox In attacks targeting Chinese…

December 4, 2025
Critical RSC bug in React and Next.js allows unauthenticated remote code execution

Critical RSC bug in React and Next.js allows unauthenticated remote code execution

A maximum severity security flaw has been disclosed in React…

December 3, 2025
India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India's Department of Telecommunications (DoT) has directed app-based telecom service…

December 2, 2025
India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India's Ministry of Telecommunications has reportedly asked major mobile device…

December 1, 2025
CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated…

November 30, 2025

You Might Also Like

North Korean hacker lures defense engineer with fake job to steal drone secrets
Technology

North Korean hacker lures defense engineer with fake job to steal drone secrets

4 Min Read
Confucius hackers hit Pakistan with new Wooperstealer and Anonymous malware
Technology

Confucius hackers hit Pakistan with new Wooperstealer and Anonymous malware

3 Min Read
WhatsApp malware 'Maverick' hijacks browser sessions and targets Brazil's largest banks
Technology

WhatsApp malware ‘Maverick’ hijacks browser sessions and targets Brazil’s largest banks

9 Min Read
Bloody Wolf expands Java-based NetSupport RAT attacks in Kyrgyzstan and Uzbekistan
Technology

Bloody Wolf expands Java-based NetSupport RAT attacks in Kyrgyzstan and Uzbekistan

3 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?