InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: Critical RSC bug in React and Next.js allows unauthenticated remote code execution
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > Critical RSC bug in React and Next.js allows unauthenticated remote code execution
Technology

Critical RSC bug in React and Next.js allows unauthenticated remote code execution

December 3, 2025 2 Min Read
Share
Critical RSC bug in React and Next.js allows unauthenticated remote code execution
SHARE

A maximum severity security flaw has been disclosed in React Server Components (RSC) that could allow remote code execution if successfully exploited.

This vulnerability is tracked as CVE-2025-55182 and has a CVSS score of 10.0.

The React team said in an alert issued today that this allows for “unauthenticated remote code execution by exploiting a flaw in the way React decodes payloads sent to React server function endpoints.”

“Even if your app doesn’t implement the React Server Function endpoint, it may still be vulnerable if it supports React Server components.”

According to cloud security company Wiz, the issue is a case of logical deserialization caused by processing the RSC payload in an insecure manner. As a result, an unauthenticated attacker could make a malicious HTTP request to any server function endpoint and, once deserialized by React, could execute arbitrary JavaScript code on the server.

This vulnerability affects versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of the following npm packages:

  • react-server-dom-webpack
  • react server dumb parcel
  • react server dumb turbo pack

This issue is addressed in versions 19.0.1, 19.1.2, and 19.2.1. New Zealand-based security researcher Lachlan Davidson is credited with discovering and reporting the flaw on November 29, 2025.

Note that this vulnerability also affects Next.js that uses App Router. This issue has been assigned CVE identifier CVE-2025-66478 (CVSS score: 10.0). Affects versions 14.3.0-canary.77 and above, 15 and above, and 16 and above. Patched versions are 16.0.7, 15.5.7, 15.4.8, 15.3.6, 15.2.6, 15.1.9, and 15.0.5.

However, any library that bundles RSC may be affected by this flaw. This includes, but is not limited to, Vite RSC plugin, Parcel RSC plugin, React Router RSC preview, RedwoodJS, and Waku.

See also  Microsoft discovers 'whisper leak' attack that identifies AI chat topics in encrypted traffic

Wiz said that 39% of cloud environments have instances vulnerable to CVE-2025-55182 and CVE-2025-66478. Given the severity of the vulnerability, we recommend that users apply the fix as soon as possible for optimal protection.

Share This Article
Twitter Copy Link
Previous Article Destiny 2 Renegades has had a huge surge on Steam, but even Star Wars mania can't recapture the highs of my favorite FPS Destiny 2 Renegades has had a huge surge on Steam, but even Star Wars mania can’t recapture the highs of my favorite FPS
Next Article Trump's approval rating plummets due to economic crisis Trump’s approval rating plummets due to economic crisis

Latest News

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

threat actor known as silver fox In attacks targeting Chinese…

December 4, 2025
Critical RSC bug in React and Next.js allows unauthenticated remote code execution

Critical RSC bug in React and Next.js allows unauthenticated remote code execution

A maximum severity security flaw has been disclosed in React…

December 3, 2025
India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India's Department of Telecommunications (DoT) has directed app-based telecom service…

December 2, 2025
India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India's Ministry of Telecommunications has reportedly asked major mobile device…

December 1, 2025
CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated…

November 30, 2025

You Might Also Like

Quantum Hacks to AI Defenses
Technology

From quantum hacks to AI defense – an expert guide to building unbreakable cyber resilience

7 Min Read
Russian hackers create 4,300 fake travel websites to steal hotel guests' payment data
Technology

Russian hackers create 4,300 fake travel websites to steal hotel guests’ payment data

6 Min Read
Five new exploited bugs listed in CISA catalog - Oracle and Microsoft also targeted
Technology

Five new exploited bugs listed in CISA catalog – Oracle and Microsoft also targeted

3 Min Read
Two new Super Micro BMC bugs allow malicious firmware to circumvent the trust security route
Technology

Two new Super Micro BMC bugs allow malicious firmware to circumvent the trust security route

4 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?