
React and Next.js Vulnerabilities Enable Remote Code Execution
A critical vulnerability was announced today affecting React Server Components (RSC), which affects React (CVE-2025-55182) and all frameworks using RSC, notably Next.js (CVE-2025-66478). Both vulnerabilities were given a CVSSv3 10.0 score, marking them as highly critical. The source of these vulnerabilities was found in RSC’s ReactFlight protocol – a protocol used by React 19 to …










