A critical remote code execution vulnerability (CVE-2025-55182, CVSS 10.0) was discovered in React Server Components affecting versions 19.0 through 19.2.0. The flaw allows unauthenticated attackers to execute arbitrary code by exploiting how React decodes payloads sent to Server Function endpoints. Patches are available in

3m read time From react.dev
Post cover image
Table of contents
Affected frameworks and bundlersVulnerability overviewTimelineAttribution

Sort: