Vulnerability threat dossier

CVE-2025-55182

facebookreact

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

VTP deterministic threat67.0of 100 · CVSS excluded

VTP analyst assessment

React Server Components pre-authentication RCE

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityCRITICAL
AI confidence95%
Public exploitation · VTP factKEV

Assessment

React Server Components can unsafely deserialize HTTP payloads and allow pre-authentication remote code execution. CISA KEV and ENISA EU KEV list known exploitation. CISA KEV notes known ransomware campaign use.

Why it matters

  • Affected Server Function endpoints can process attacker-controlled payloads before authentication.
  • Review in your environment: if you use the listed React Server Components packages, check versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The supplied public exploitation sources do not establish VTP observation.

The supplied template evidence does not prove reliable exploitation.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Unexpected payloads sent to React Server Function endpoints.

AI baseline history (4)
  1. BASELINE ASSESSED
    React Server Components pre-authentication RCEgpt-5.6-terra · low
  2. BASELINE ASSESSED
    React Server Components remote code executiongpt-5.6-terra · low
  3. BASELINE ASSESSED
    React Server Components pre-authentication RCEgpt-5.6-sol · high
  4. BASELINE ASSESSED
    React Server Components pre-authentication RCEgpt-5.6-sol · high
Technical severityCRITICALCVSS 10.0 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

1 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:NUCLEI:ca9197a381d96099b4ffbe36367e35c6a38d253fACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2025-55182ACTIVE
Evidence
04

Event history

Threat timeline

  1. 10:0908 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  2. 00:0005 Dec
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

  3. 00:0005 Dec
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Exploit tooling coverage changed for 67 CVEs

ProjectDiscovery nuclei-templates recorded exploit-tooling coverage changes for 67 CVEs in this pinned revision. 67 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2017-18362CVE-2018-6961CVE-2018-9206CVE-2019-12989CVE-2019-13608CVE-2019-25213CVE-2019-9082CVE-2020-11732CVE-2020-12832CVE-2020-3952CVE-2020-9039CVE-2021-20617CVE-2021-21246CVE-2021-22175CVE-2021-23394CVE-2021-24212CVE-2021-24786CVE-2021-28799CVE-2021-3287CVE-2021-35042CVE-2021-41419CVE-2021-4374CVE-2021-4462CVE-2022-29081CVE-2022-36923CVE-2022-38130CVE-2023-3277CVE-2023-33193CVE-2023-34048CVE-2023-38952CVE-2023-52163CVE-2023-5815CVE-2024-23108CVE-2024-2863CVE-2024-28986CVE-2024-53900CVE-2024-6250CVE-2025-10204CVE-2025-1023CVE-2025-12055CVE-2025-12480CVE-2025-1302CVE-2025-13315CVE-2025-27817CVE-2025-32429CVE-2025-37164CVE-2025-4210CVE-2025-44137CVE-2025-47188CVE-2025-47445CVE-2025-51482CVE-2025-52472CVE-2025-52691CVE-2025-54236CVE-2025-55182CVE-2025-55523CVE-2025-56520CVE-2025-58360CVE-2025-66516CVE-2025-68645CVE-2025-8110CVE-2025-8943CVE-2026-21859CVE-2026-21877CVE-2026-23550CVE-2026-23760CVE-2026-56292
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2025-55182

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2025-55182
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score67.0vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.96 / 20
Exploit availability7.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
10 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-502
CPE records
76
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.