InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: Critical RSC bug in React and Next.js allows unauthenticated remote code execution
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > Critical RSC bug in React and Next.js allows unauthenticated remote code execution
Technology

Critical RSC bug in React and Next.js allows unauthenticated remote code execution

December 3, 2025 2 Min Read
Share

A maximum severity security flaw has been disclosed in React Server Components (RSC) that could allow remote code execution if successfully exploited.

This vulnerability is tracked as CVE-2025-55182 and has a CVSS score of 10.0.

The React team said in an alert issued today that this allows for “unauthenticated remote code execution by exploiting a flaw in the way React decodes payloads sent to React server function endpoints.”

“Even if your app doesn’t implement the React Server Function endpoint, it may still be vulnerable if it supports React Server components.”

According to cloud security company Wiz, the issue is a case of logical deserialization caused by processing the RSC payload in an insecure manner. As a result, an unauthenticated attacker could make a malicious HTTP request to any server function endpoint and, once deserialized by React, could execute arbitrary JavaScript code on the server.

This vulnerability affects versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of the following npm packages:

  • react-server-dom-webpack
  • react server dumb parcel
  • react server dumb turbo pack

This issue is addressed in versions 19.0.1, 19.1.2, and 19.2.1. New Zealand-based security researcher Lachlan Davidson is credited with discovering and reporting the flaw on November 29, 2025.

Note that this vulnerability also affects Next.js that uses App Router. This issue has been assigned CVE identifier CVE-2025-66478 (CVSS score: 10.0). Affects versions 14.3.0-canary.77 and above, 15 and above, and 16 and above. Patched versions are 16.0.7, 15.5.7, 15.4.8, 15.3.6, 15.2.6, 15.1.9, and 15.0.5.

However, any library that bundles RSC may be affected by this flaw. This includes, but is not limited to, Vite RSC plugin, Parcel RSC plugin, React Router RSC preview, RedwoodJS, and Waku.

See also  India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

Wiz said that 39% of cloud environments have instances vulnerable to CVE-2025-55182 and CVE-2025-66478. Given the severity of the vulnerability, we recommend that users apply the fix as soon as possible for optimal protection.

Share This Article
Twitter Copy Link
Previous Article Destiny 2 Renegades has had a huge surge on Steam, but even Star Wars mania can't recapture the highs of my favorite FPS Destiny 2 Renegades has had a huge surge on Steam, but even Star Wars mania can’t recapture the highs of my favorite FPS
Next Article Trump's approval rating plummets due to economic crisis Trump’s approval rating plummets due to economic crisis

You Might Also Like

Shai-Hulud v2 campaign spreads from npm to Maven, exposing thousands of secrets
Technology

Shai-Hulud v2 campaign spreads from npm to Maven, exposing thousands of secrets

6 Min Read
Grafana patch CVSS 10.0 SCIM flaw allows impersonation and privilege escalation
Technology

Grafana patch CVSS 10.0 SCIM flaw allows impersonation and privilege escalation

2 Min Read
Zero-click agent browser attack could delete entire Google Drive using crafted email
Technology

Zero-click agent browser attack could delete entire Google Drive using crafted email

5 Min Read
Malware Delivery Channels
Technology

North Korean hackers turn JSON service into covert malware delivery channel

3 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?