React Server Components Flaw CVE-2025-55182 Actively Exploited

Summary
CVE-2025-55182, an unauthenticated remote-code-execution flaw in React Server Components affecting React 19 and related frameworks such as Next.js, is being actively exploited. Apply the listed patches and review dependencies.
Key points
- The insecure deserialization flaw can allow arbitrary server-side code execution through a single malicious HTTP request, without authentication.
- React versions 19.0.0–19.2.0 and Next.js versions integrating vulnerable React Server Components are identified as affected.
- The article lists patched React versions 19.0.1, 19.1.2, and 19.2.1, and patched Next.js versions from 15.0.5 through 16.0.7.
- Aqua reports that intelligence teams observed exploitation by China-nexus groups, mass-scanning botnets, and opportunistic attackers.
- Observed post-exploitation attempts include deploying remote shells and cryptominers, harvesting credentials from environment variables, and establishing persistence.
- Review direct and transitive dependencies, identify affected assets, upgrade to patched versions, and use runtime controls as a mitigation.
Article Details
- Event Type
- Active exploitation of an unauthenticated remote-code-execution vulnerability
- Impact
- Successful exploitation can enable full server compromise. The article reports field observations of attackers dropping remote shells, deploying cryptominers, attempting to harvest credentials, and establishing persistence; it does not identify specific compromised organizations.