A critical security vulnerability (CVE-2025-55182) has been discovered in React Server Components, affecting React 19.x and Next.js 15.x/16.x applications. This remote code execution vulnerability requires immediate patching.
Affected Versions:
- React: All versions of React 19.x prior to 19.1.0
- Next.js: Versions 15.x and 16.x with App Router enabled
Immediate Action Required:
- React 19: Upgrade to version 19.1.0 or later
- Next.js 15: Upgrade to latest patched versions
This vulnerability allows unauthenticated remote code execution and has already been exploited by threat actors. Treat this as a critical security incident.