CVE-2025-55182 – React Server Components RCE via Flight Payload Deserialization

React Server Components promise less client-side JavaScript, but that convenience can hide serious risk. Learn how CVE-2025-55182 (CVSS 10.0) enables critical RCE in the RSC ecosystem, why it happened, and how the public exploit works against React’s server-side handling.

The post CVE-2025-55182 – React Server Components RCE via Flight Payload Deserialization appeared first on OffSec.

This article has been indexed from OffSec

Read the original article: