Known vulnerability record

CVE-2025-55182

Meta React Server Components Remote Code Execution Vulnerability

Stable IDcve:CVE-2025-55182Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Meta React Server Components Remote Code Execution Vulnerability

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

Keep the signals separate

CVSS severitycriticalScore 10 · source Meta
EPSS probability99.6%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2025-12-05
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2025-12-03
CVE modified
2026-08-04
KEV date added
2025-12-05
Dataset fetched
2026-08-21T03:54:58.997Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.