GHSA-fv66-9v8q-g76r
React Server Components are Vulnerable to RCE
Quick fix
GHSA-fv66-9v8q-g76r — react-server-dom-webpack: upgrade to the fixed version with the command below.
npm install react-server-dom-webpack@19.0.1Details
### Impact
There is an unauthenticated remote code execution vulnerability in React Server Components.
We recommend upgrading immediately.
The vulnerability is present in versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 of: * [react-server-dom-webpack](https://www.npmjs.com/package/react-server-dom-webpack) * [react-server-dom-parcel](https://www.npmjs.com/package/react-server-dom-parcel) * [react-server-dom-turbopack](https://www.npmjs.com/package/react-server-dom-turbopack?activeTab=readme)
### Patches
A fix was introduced in versions [19.0.1](https://github.com/facebook/react/releases/tag/v19.0.1), [19.1.2](https://github.com/facebook/react/releases/tag/v19.1.2), and [19.2.1](https://github.com/facebook/react/releases/tag/v19.2.1). If you are using any of the above packages please upgrade to any of the fixed versions immediately.
If your app’s React code does not use a server, your app is not affected by this vulnerability. If your app does not use a framework, bundler, or bundler plugin that supports React Server Components, your app is not affected by this vulnerability.
### References
See the [blog post](https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components) for more information and upgrade instructions.
Are you affected?
Enter the version of the package you're using.
Affected packages
19.0.0Fixed in: 19.0.1npm install react-server-dom-webpack@19.0.119.1.0Fixed in: 19.1.2npm install react-server-dom-webpack@19.1.219.2.0Fixed in: 19.2.1npm install react-server-dom-webpack@19.2.119.0.0Fixed in: 19.0.1npm install react-server-dom-turbopack@19.0.119.1.0Fixed in: 19.1.2npm install react-server-dom-turbopack@19.1.219.2.0Fixed in: 19.2.1npm install react-server-dom-turbopack@19.2.119.0.0Fixed in: 19.0.1npm install react-server-dom-parcel@19.0.119.1.0Fixed in: 19.1.2npm install react-server-dom-parcel@19.1.219.2.0Fixed in: 19.2.1npm install react-server-dom-parcel@19.2.1References
- https://github.com/facebook/react/security/advisories/GHSA-fv66-9v8q-g76r[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-55182[ADVISORY]
- https://github.com/facebook/react/pull/35277[WEB]
- https://github.com/facebook/react/commit/7dc903cd29dac55efb4424853fd0442fef3a8700[WEB]
- https://github.com/ejpir/CVE-2025-55182-poc[WEB]
- https://github.com/facebook/react[PACKAGE]
- https://github.com/facebook/react/releases/tag/v19.0.1[WEB]
- https://github.com/facebook/react/releases/tag/v19.1.2[WEB]
- https://github.com/facebook/react/releases/tag/v19.2.1[WEB]
- https://news.ycombinator.com/item?id=46136026[WEB]
- https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components[WEB]
- https://www.facebook.com/security/advisories/cve-2025-55182[WEB]
- http://www.openwall.com/lists/oss-security/2025/12/03/4[WEB]