A vulnerability has been identified in React. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.
Note:
The vulnerability (CVE-2025-55182) has been identified in the React Server Components (RSC) protocol, it allows unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints.
[Updated on 2025-12-05]
Updated Description and Risk Level. Proof of Concept exploit code Is publicly available for CVE-2025-55182. Hence, the risk level is rated from Medium Risk to High Risk.