# Critical Security Vulnerability in React Server Components

DevFeed: [Critical Security Vulnerability in React Server Components](<https://devfeed.tech/articles/critical-security-vulnerability-in-react-server-components-2994.md>)

Original publisher: [Read original article](<https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components>)

Author: The React Team

Published: 2025-12-03T00:00:00Z

Content type: article

Language: en

Sources: [React Blog](<https://devfeed.tech/sources/react-blog.md>)

Topics: [React](<https://devfeed.tech/topics/react.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Next.js](<https://devfeed.tech/topics/next-js.md>), [React Router](<https://devfeed.tech/topics/react-router.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [packages](<https://devfeed.tech/tags/packages.md>), [react](<https://devfeed.tech/tags/react.md>), [remote-code-execution-vulnerability](<https://devfeed.tech/tags/remote-code-execution-vulnerability.md>), [router](<https://devfeed.tech/tags/router.md>), [security](<https://devfeed.tech/tags/security.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

The React Team disclosed an unauthenticated remote code execution vulnerability in React Server Components, tracked as CVE-2025-55182 and rated CVSS 10.0. The issue affects certain React 19 releases and related frameworks and bundlers, including Next.js and React Router. Users should upgrade immediately to a patched version.

## Source excerpt

There is an unauthenticated remote code execution vulnerability in React Server Components. A fix has been published in versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately.