React Server Components Flaw CVE-2025-55182 Actively Exploited

· Original article ↗

Summary

CVE-2025-55182, an unauthenticated remote-code-execution flaw in React Server Components affecting React 19 and related frameworks such as Next.js, is being actively exploited. Apply the listed patches and review dependencies.

Key points

  • The insecure deserialization flaw can allow arbitrary server-side code execution through a single malicious HTTP request, without authentication.
  • React versions 19.0.0–19.2.0 and Next.js versions integrating vulnerable React Server Components are identified as affected.
  • The article lists patched React versions 19.0.1, 19.1.2, and 19.2.1, and patched Next.js versions from 15.0.5 through 16.0.7.
  • Aqua reports that intelligence teams observed exploitation by China-nexus groups, mass-scanning botnets, and opportunistic attackers.
  • Observed post-exploitation attempts include deploying remote shells and cryptominers, harvesting credentials from environment variables, and establishing persistence.
  • Review direct and transitive dependencies, identify affected assets, upgrade to patched versions, and use runtime controls as a mitigation.

Article Details

Event Type
Active exploitation of an unauthenticated remote-code-execution vulnerability
Impact
Successful exploitation can enable full server compromise. The article reports field observations of attackers dropping remote shells, deploying cryptominers, attempting to harvest credentials, and establishing persistence; it does not identify specific compromised organizations.

MITRE ATT&CK

CVE

Vendors

Products

Countries

Related Articles