• News/
  • https://www.theregister.com/2025/12/03/exploitation_is_imminent_react_vulnerability/

'Exploitation is imminent' as 39 percent of cloud environs have max-severity React hole

The Register
·
Jessica Lyons
·
Published Dec 3, 2025
·
Updated

A maximum-severity flaw in the widely used JavaScript library React, and several React-based frameworks including Next.js allows unauthenticated, remote attackers to execute malicious code on vulnerable instances. The flaw is easy to abuse, and mass exploitation is "imminent," according to security researchers. The React team disclosed the unauthenticated remote code execution (RCE) vulnerability in React Server Components on Wednesday. It's tracked as CVE-2025-55182 and received a maximum 10.0 CVSS severity rating. This is a big deal because much of the internet is built on React – one estimate suggests 39 percent of cloud environments are vulnerable to this flaw. This issue therefore deserves a prominent place on your to-do list. The bug affects versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of: It also affects the default configuration of several React frameworks and bundlers including next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk. The project's maintainers say upgrading to versions 19.0.1, 19.1.2, and 19.2.1 fixes the flaw. "We recommend upgrading immediately," the React team said in a Wednesday security advisory. "CVE-2025-55182 represents a major risk to users of one of the world's most widely used web application frameworks," Benjamin Harris, founder and CEO of exposure management tools vendor watchTowr, told The Register. "Exploitation requires few prerequisites [and] there should be no doubt that in-the-wild exploitation is imminent as soon as attac...

Read full article

Affected Software

10 affected components
Meta React=19.0
Meta React=19.1.0
Meta React=19.1.1
Meta React=19.2.0
Vercel Next.js
React Training react-router
Waku waku
Parcel @parcel/rsc
Vite @vitejs/plugin-rsc
rwsdk rwsdk
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical security vulnerability in the React JavaScript library and several related frameworks that poses significant risks of exploitation.

2

What security implications are discussed in the article?

The article highlights that unauthenticated remote attackers can execute malicious code on vulnerable systems due to the flaw.

3

Which software products are affected by this vulnerability?

The vulnerability affects Meta React, Vercel Next.js, React Training react-router, Waku waku, Parcel @parcel/rsc, Vite @vitejs/plugin-rsc, and rwsdk rwsdk.

4

How severe is the vulnerability mentioned in the article?

The vulnerability is classified as maximum-severity, indicating a high risk for exploitation.

5

What does the article suggest about the potential for exploitation?

The article suggests that mass exploitation of the vulnerability is imminent due to its ease of abuse.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203