top of page
Critical Remote Code Execution Vulnerabilities Discovered in React Server Components and Next.js
3 december 2025 om 20:59:18
stepsecurity.io
Critical remote code execution vulnerabilities discovered in React Server Components and Next.js framework. Two CVEs identified: CVE-2025-55182 and CVE-2025-66478. These vulnerabilities affect popular React-based web applications and Next.js implementations. The critical nature suggests potential for widespread impact given the popularity of these frameworks. Remote code execution capability makes these high-priority security issues requiring immediate attention.
Related links:
Related CVE's:
CVE-2025-55182CVE-2025-66478
Related threat actors:
No threat actors found in this article
Affected products:
React Server ComponentsNext.js
IOC's:
No IOCs found in this article
bottom of page
