TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Trend Micro Research

Critical React Server Components Vulnerability CVE-2025-55182: What Security Teams Need to Know

Peter Girnus · 2025-12-05 · Read original ↗

ATT&CK techniques detected

2 predictions
T1190Exploit Public-Facing Application
58%
"critical react server components vulnerability cve - 2025 - 55182 : what security teams need to know exploits & vulnerabilities critical react server components vulnerability cve - 2025 - 55182 : what security teams need to know cve - 2025 - 55182 is a critical ( cvss 10. 0 ) pre…"
T1190Exploit Public-Facing Application
32%
"vulnerability since disclosure. we ' ve been analyzing telemetry, reviewing proof - of - concept exploits from the security community and developing detection signatures for enterprise environments. we have observed active exploitation attempts in the wild. these attacks align wi…"

Summary

CVE-2025-55182 is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components used in React.js, Next.js, and related frameworks (see the context section for a more exhaustive list of affected frameworks).