Skip to content
COOEY

EXPOSURES › CVE-2025-55182

CVE-2025-55182

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-12-05 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-55182 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildsupply-chainunpatched

Meta's React Server Components suffered a critical unauthenticated remote code execution flaw actively exploited by ransomware actors.

An unauthenticated remote code execution vulnerability in Meta's React Server Components allowed attackers to execute arbitrary code on React Server Function endpoints. This failure is critical for DIB organizations because it represents a high-severity, actively exploited supply-chain risk that could compromise cloud-native applications and violate CMMC/NIST 800-171 controls around software integrity and remote access. Organizations must urgently patch React Server Components and assess their exposure to similar flaws in widely used frameworks.

Shame score — A critical RCE flaw in a widely used framework was actively exploited by ransomware actors, demonstrating severe negligence in patching and vulnerability management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.