A critical vulnerability has been found in recent versions of Meta’s React Server Components. The company is asking users of the software to update immediately to a patched version. The flaw is rated 10/10.
It concerns CVE-2025-55182, which allows arbitrary code execution on the victim’s system, according to Meta. The company is sharing few details about the flaw, but an attacker can, with a malicious HTTP request to a React Server endpoint, trigger arbitrary code execution on that server.
The vulnerability affects versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of React Server Components. Meta advises users to carefully check whether they are using it, since other applications, such as Next.js, also use React Server Components. The patch is available in versions 19.0.1, 19.1.2, and 19.2.1, the company says.