CVE-2025-55182 – Critical Remote Code Execution in React Server Components & Next.js

Key takeaways

  • Critical RCE affecting React Server Components (versions 19.0.0‑19.2.0) and Next.js applications.
  • Actively exploited in the wild; cryptomining and reverse‑shell payloads observed.
  • Listed in CISA KEV – mandatory for federal agencies.
  • Immediate patch or upgrade required; apply vendor‑provided mitigations.
  • Monitor for exploitation signals (e.g., “React2Shell” scanning toolkit, anomalous outbound connections).

Overview

On December 3 2025, a pre‑authentication remote code execution vulnerability was disclosed in React Server Components and the Next.js framework. The flaw, tracked as CVE-2025-55182, allows an attacker to send a crafted HTTP request to a server‑function endpoint that deserializes the payload without validation, resulting in full system compromise. The vulnerability carries a Critical CVSS 10.0 score (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and is listed in the CISA KEV catalog as “Meta React Server Components Remote Code Execution Vulnerability”.


Technical Details

  • Vulnerable packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack in versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0.
  • Root cause: Unsafe deserialization of attacker‑controlled data (CWE-502) in the Server Component runtime.
  • Attack vector: Unauthenticated HTTP request (network‑accessible, low complexity) to any Server Function endpoint.
  • Observed exploitation: Threat‑intel feeds report cryptomining and reverse‑shell payloads delivered via the “React2Shell” chain. Two IP addresses alone account for >56 % of exploitation traffic (cryptominer vs. reverse shell).
  • Timeline: Active exploitation reported repeatedly from early February 2026 through March 2026, with multiple “ILovePoop” scanning tool deployments targeting millions of IPs.

Severity & Impact

MetricValue
SeverityCritical
CVSSCVSS 10.0 (3.1)
CWECWE-502 (Deserialization of Untrusted Data)
ImpactFull system compromise – attacker‑controlled code execution, enabling data theft, cryptomining, or lateral movement
CISA KEVCISA KEV

Affected Products

The vulnerability impacts React Server Components (versions 19.0.0‑19.2.0) and any Next.js application that bundles these components, regardless of the underlying Node.js version. Vendors involved are Meta (Facebook) and Vercel. For the exhaustive list of affected versions, see the CVE page: https://vulnsocial.com/cve/CVE-2025-55182.


What to Do Now

  • Inventory: Scan your codebase and dependency manifests (package.json, yarn.lock, pnpm-lock.yaml) for the vulnerable package versions.
  • Prioritize: Flag any production services as high‑risk; exploitation is already observed.
  • Patch: Apply the vendor‑released patch immediately (see references).
  • Temporary mitigation: If patching is not possible, disable exposed Server Function endpoints or enforce strict input validation.
  • Monitor: Deploy detection for the “React2Shell” scanning toolkit (e.g., signatures for the “ILovePoop” scanner) and watch outbound traffic to known cryptomining pools. Track real‑time activity on the VulnSocial feed: https://vulnsocial.com/cve/CVE-2025-55182.
  • Incident response: Treat any compromised host as fully breached – rotate secrets, review logs, and consider rebuilding containers from clean images.

Remediation & Mitigation

  1. Update dependencies – Upgrade React Server Components and Next.js to the latest non‑vulnerable releases. Example:
    npm install react@latest next@latest
    
  2. Apply vendor patches – Follow the official advisories:
  3. Validate inputs – Implement server‑side validation for all data reaching Server Function endpoints; reject malformed payloads before deserialization.
  4. Restrict exposure – Ensure Server Function endpoints are not publicly reachable unless required; use firewalls or API gateways.
  5. Deploy WAF rules – Block known malicious payload patterns associated with React2Shell (e.g., base64‑encoded JavaScript that spawns shells).
  6. Continuous monitoring – Subscribe to the VulnSocial CVE feed for daily activity metrics and integrate alerts into your SIEM.

Bottom line

The CVE-2025-55182 vulnerability is a Critical RCE that is actively exploited across the internet. Immediate patch or upgrade of React Server Components and Next.js is mandatory, especially for organizations subject to CISA KEV compliance. Ongoing monitoring, input validation, and network hardening are essential to mitigate residual risk.


References

#CVE202555182 #Critical #RCE #CISAKEV #React #Nextjs #ReactServerComponents