https://seclists.org/oss-sec/2025/q4/232: CVE-2025-55182: RCE in act Server Components
Published Dec 3, 2025
·Updated
Affected Software
3 affected components
Meta react-server-dom-webpack
Meta react-server-dom-parcel
Meta react-server-dom-turbopack
Frequently Asked Questions
1
What is the severity of CVE-2025-55182?
CVE-2025-55182 is classified as a critical vulnerability due to its potential for pre-authentication remote code execution.
2
How do I fix CVE-2025-55182?
To mitigate CVE-2025-55182, immediately update your Meta react-server-dom packages to the latest versions released after the vulnerability announcement.
3
Which software is affected by CVE-2025-55182?
CVE-2025-55182 affects Meta react-server-dom-webpack, Meta react-server-dom-parcel, and Meta react-server-dom-turbopack.
4
Is there a workaround for CVE-2025-55182?
There are no recommended workarounds for CVE-2025-55182; upgrading to the patched versions is necessary.
5
What kind of attack does CVE-2025-55182 allow?
CVE-2025-55182 allows attackers to execute arbitrary code remotely before authentication.