EXPOSURES › CVE-2025-55182
CVE-2025-55182
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMeta's React Server Components suffered a critical unauthenticated remote code execution flaw actively exploited by ransomware actors.
An unauthenticated remote code execution vulnerability in Meta's React Server Components allowed attackers to execute arbitrary code on React Server Function endpoints. This failure is critical for DIB organizations because it represents a high-severity, actively exploited supply-chain risk that could compromise cloud-native applications and violate CMMC/NIST 800-171 controls around software integrity and remote access. Organizations must urgently patch React Server Components and assess their exposure to similar flaws in widely used frameworks.
Shame score — A critical RCE flaw in a widely used framework was actively exploited by ransomware actors, demonstrating severe negligence in patching and vulnerability management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.