Hello, this is Sparrow.
A new security vulnerability, CVE-2025-55182, has been disclosed, allowing unauthenticated Remote Code Execution (RCE) in environments using React Server Components. This vulnerability has been rated Critical (CVSS 10.0) and can be exploited across various development frameworks and service environments, requiring immediate attention.
■ Overview
- CVE ID: CVE-2025-55182
- Severity: Critical (CVSS 10.0)
- Affected Range and Fixed Versions: (details to be referenced in the table)

(* Reference: NVD – CVE-2025-55182 )
■ Recommended Actions
-
Project Review
-
Check the versions of React and Next.js currently in use and verify whether any vulnerable versions are deployed.
-
-
Apply Security Patches (refer to the table above)
-
For React, update to version 19.01 / 19.1.2 / 19.2.1 or later.
-
For Next.js, update to 15.05 or later, or 16.07 or later.
-
This vulnerability has been actively exploited shortly after disclosure, with actual intrusion cases already reported.
Prompt environment validation and timely patch application are essential.
Sparrow will provide full support to help minimize any potential impact on your organization and to ensure stable service operations.
If you have any questions, please feel free to contact: alex@sparrow.im