- Response Critical Vulnerability (CVE-2025-55182) Allows RCE pre-authentication on response server components
- This affects versions 19.0–19.2.0 and frameworks such as Next, React Router, Vitae; Patches released in 19.0.1, 19.1.2, 19.2.1
- Experts warn that exploitation is inevitable with a success rate close to 100%; An emergency update is highly recommended
React is one of the most popular JavaScript libraries powering the modern web. Recently, researchers discovered a high-intensity vulnerability. This bug could allow even ill-prepared threat actors to execute malicious code (RCE) under malicious circumstances.
Earlier this week, the React team published a new security advisory detailing a pre-authentication bug in multiple versions of multiple packages that affects React Server components. Affected versions include 19.0, 19.1.0, 19.1.1, and 19.2.0, react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack.
The bug is currently tracked as CVE-2025-55182 and has a severity score of 10/10 (Critical).
Exploitation is inevitable, no doubt
According to him, this bug also affected several React frameworks and default package configurations, including Next, React-Router, Waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk.
The versions that fixed the bug are 19.0.1, 19.1.2, and 19.2.1, and the response encourages all users to apply the fix as soon as possible. “We recommend an immediate upgrade,” the response team said.
According to RecordAbout two out of five forces react in all cloud environments, so the attack surface is large, to say the least. Facebook, Instagram, Netflix, Airbnb, Shopify, and other giants of today’s Internet depend on feedback, as do millions of other developers.
Benjamin Harris, founder and CEO of exposure management tools provider Watchtower, told the publication that the flaw would “definitely” be used in the wild. In fact, he believes abuse is “inevitable”, especially now that the advice has been made public.
Wiz was able to verify the bug and said that “exploitation of this vulnerability was highly accurate, with a near 100% success rate and could be used to execute all remote code.”
In other words, now is not the time to relax: fixing this flaw should be everyone’s number one priority.
through Record
The best antivirus for any budget
Follow TechRadar on Google News I Add us as your preferred source Get news, reviews and opinions from our experts in your feed. Don’t forget to click the follow button!
And, of course, you can Siga TechRadar on TikTok Get our regular updates in the form of news, reviews, unboxing and videos. WhatsApp very

