CISA Adds Critical React2Shell Vulnerability to KEV Catalog Following Active Exploitation
A critical vulnerability affecting Meta React Server Components, identified as CVE-2025-55182 , has been included in the Known Exploited Vulnerabilities (KEV) catalog by CISA. This remote code execution vulnerability presents an immediate risk to…
A critical vulnerability affecting Meta React Server Components, identified as CVE-2025-55182 , has been included in the Known Exploited Vulnerabilities (KEV) catalog by CISA. This remote code execution vulnerability presents an immediate risk to organizations utilizing React Server Components.
The vulnerability arises from a flaw in the decoding of payloads sent to React Server Function endpoints . Exploitation of this flaw can result in unauthenticated remote code execution, potentially compromising systems without requiring user interaction.
CISA has assigned a critical severity rating to this vulnerability due to its potential for widespread impact. The agency added CVE-2025-55182 to its KEV catalog on December 5, 2025, with a mandatory remediation deadline of December 26, 2025, for federal agencies and critical infrastructure operators. This 21-day window highlights the urgent nature of the threat.
Organizations using Meta React Server Components should prioritize immediate remediation efforts. CISA recommends applying vendor-provided mitigations or following applicable BOD 22-01 guidance for cloud services. If patches or mitigations cannot be implemented, discontinuing use of the affected product may be necessary.
This remote code execution vulnerability presents an immediate risk to organizations utilizing React Server Components.
While no confirmed connections between this vulnerability and ransomware campaigns have been documented, the critical nature and active exploitation status suggest heightened risk. Organizations should monitor threat intelligence feeds and security advisories for updates.
The inclusion of CVE-2025-55182 in CISA's KEV catalog underscores the importance of effective vulnerability management and rapid patch deployment. Organizations should:
Assess their infrastructure for affected React Server Components ( RSC ) deployments. Take action before the December 26 deadline. Review current React implementations and test compatibility with available patches in controlled environments. Develop deployment plans to minimize operational disruption while ensuring comprehensive coverage across all affected systems.
Based on reporting by Cyber Security News.
