A critical remote code execution vulnerability (CVE-2025-55182, CVSS 10.0) was discovered in React Server Components affecting versions 19.0 through 19.2.0. The flaw allows unauthenticated attackers to execute arbitrary code by exploiting how React decodes payloads sent to Server Function endpoints. Patches are available in versions 19.0.1, 19.1.2, and 19.2.1. Applications using React Server Components through frameworks like Next.js, React Router, or Waku should upgrade immediately, even if they don't explicitly implement Server Function endpoints.

3m read timeFrom react.dev
Post cover image
Table of contents
Affected frameworks and bundlersVulnerability overviewTimelineAttribution

Sort: