PT-2025-48817 · Meta · React-Server-Dom-Webpack+3

CVE-2025-55182

·

Published

2025-12-03

·

Updated

2026-08-27

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions React Server Components versions 19.0.0 through 19.2.0
Description A pre-authentication remote code execution issue exists in the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. The flaw is caused by the unsafe deserialization of payloads in the requireModule() function when processing the hasOwnProperty parameter during HTTP requests to Server Function endpoints. This allows a remote, unauthenticated attacker to execute arbitrary JavaScript code in the server context. Real-world exploitation has been observed, including the deployment of EtherRAT (a Node.js backdoor using blockchain-based C2), cryptocurrency mining, and the Weaxor ransomware, which disables Windows Defender and encrypts files with the .WEAX extension.
Recommendations Update React Server Components to a version later than 19.2.0. As a temporary mitigation, restrict access to Server Function endpoints to minimize the risk of exploitation.

Exploit

Fix

DoS

LPE

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15156
CVE-2025-55182
GHSA-FV66-9V8Q-G76R

Affected Products

React Server Components
React-Server-Dom-Parcel
React-Server-Dom-Turbopack
React-Server-Dom-Webpack