← العودة للجدول
CVE-2025-55182
Meta React Server Components Remote Code Execution Vulnerability — KEV
📅 2025-12-05
🔴 Critical 🔥 Yes CISA KEV Exploit Exploit 🎯 EPSS 85.16%

📋 الوصف الكامل

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182. | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

💻 الأنظمة المتأثرة

Meta React Server Components

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2025-55182

📡 المصدر

CISA KEV

✅ الحلول والتخفيف

Apply patch by 2025-12-12

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←