12/04/2025
Critical security alert for organizations running React Server Components and modern frameworks that implement RSC (including Next.js, React Router, Expo, Waku, Redwood SDK, Vite/Parcel RSC and others).
The React team has disclosed CVE-2025-55182, a CVSS 10.0 unauthenticated remote code ex*****on vulnerability in React Server Components. Patched React and framework versions are now available and should be treated as an emergency upgrade, not a routine patch.
Read the official advisory and upgrade instructions:
https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components
CulperSec’s security engineering team is actively reviewing customer environments, and validating mitigations across our CulperIQ customers. If your organization needs help:
• Determining whether your apps are exposed
• Prioritizing and rolling out framework upgrades
• Adding monitoring and compensating controls around affected services
Contact us at [email protected] today
The library for web and native user interfaces