
Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects
A comprehensive security scanning tool to detect CVE-2025-55182 and CVE-2025-66478 vulnerabilities in React and Next.js projects using React Server Components (RSC).
This tool scans your project for vulnerable versions of React, Next.js, and related RSC packages that are susceptible to Remote Code Execution (RCE) attacks. The vulnerability allows unauthenticated attackers to execute arbitrary code on your server.
⚠️ Critical Alert: As of December 2025, approximately 39% of cloud environments contain instances of Next.js or React with vulnerable versions. Immediate action is required if you're using React Server Components.
node_modules for vulnerable package versions"use server" directives in your codebase| Package | Description |
|---|---|
react | Core React library |
next | Next.js framework |
react-server-dom-webpack | RSC Webpack integration |
react-server-dom-parcel | RSC Parcel integration |
react-server-dom-turbopack | RSC Turbopack integration |
check.js:git clone https://github.com/yourusername/check-react-rce-cve-2025-55182.git
cd /path/to/your/project
node /path/to/check.js
You can also copy check.js directly into your project and run:
node check.js
===========================================================================
REACT RCE VULNERABILITY SCANNER (CVE-2025-55182)
===========================================================================
Scanning installed packages...
Starting Deep Codebase Scanning...
===========================================================================
AUDIT REPORT
===========================================================================
[CVE-2025-55182] React Vulnerability
---------------------------------------------------------------------------
react : 19.0.0 VULNERABLE (React 19.0.0 < 19.0.1)
react-server-dom-webpack : 19.0.0 VULNERABLE (19.0.0 < 19.0.1)
[CVE-2025-66478] Next.js Vulnerability
---------------------------------------------------------------------------
next : 15.0.3 VULNERABLE (v15.0.x < 15.0.5)
[Project Analysis]
---------------------------------------------------------------------------
Router Type : App Router (RSC-enabled)
Server Actions Usage : Detected (5 files)
===========================================================================
RISK CONCLUSION: CRITICAL (CVSS 10.0 - Remote Code Execution)
===========================================================================
⚠ ACTION REQUIRED:
Your project uses React Server Components with vulnerable packages.
This vulnerability allows unauthenticated remote code execution.
Vulnerable packages: react, next, react-server-dom-webpack
Run the following commands to patch:
> npm install react@latest react-dom@latest
> npm install next@latest
> npm update react-server-dom-webpack react-server-dom-parcel react-server-dom-turbopack
| Level | Description |
|---|---|
| 🔴 CRITICAL | Vulnerable packages detected + RSC features in use. Immediate action required. |
| 🟡 MEDIUM | Vulnerable packages detected, but RSC not actively detected. Update recommended. |
| 🟢 SAFE | No vulnerable packages or using versions before RSC support. |
| Status | Meaning |
|---|---|
VULNERABLE | Package version is affected by the CVE |
SAFE | Package is updated to a patched version |
SAFE_CLASSIC | Package version predates RSC (not affected) |
NOT INSTALLED | Package not found in project |
UNKNOWN | Unable to determine version status |
| Branch | Vulnerable Versions | Patched Version |
|---|---|---|
| React 19.0.x | 19.0.0 | ≥ 19.0.1 |
| React 19.1.x | 19.1.0, 19.1.1 | ≥ 19.1.2 |
| React 19.2.x | 19.2.0 | ≥ 19.2.1 |
| React 18.x and earlier | — | Not affected (no RSC support) |
| Branch | Patched Version |
|---|---|
| Next.js 16.0.x | ≥ 16.0.7 |
| Next.js 15.5.x | ≥ 15.5.7 |
| Next.js 15.4.x | ≥ 15.4.8 |
| Next.js 15.3.x | ≥ 15.3.6 |
| Next.js 15.2.x | ≥ 15.2.6 |
| Next.js 15.1.x | ≥ 15.1.9 |
| Next.js 15.0.x | ≥ 15.0.5 |
| Next.js 14.3.0-canary.77+ | ⚠️ Vulnerable (canary with Flight Protocol) |
| Next.js 14.x (stable) | Not affected |
| Next.js 13.x | Not affected |
The following configurations are NOT affected by these vulnerabilities:
Severity: CRITICAL (CVSS 10.0)
Affected Packages:
react-server-dom-webpackreact-server-dom-parcelreact-server-dom-turbopackVulnerability Type: Insecure Deserialization
Description:
A critical Remote Code Execution (RCE) vulnerability exists in the react-server package, which is integral to React Server Components (RSC). The flaw stems from an insecure deserialization vulnerability within the RSC "Flight" protocol.
The vulnerability allows an unauthenticated attacker to achieve remote code execution on the server by sending a specially crafted HTTP request to any Server Function endpoint. Even applications that do not explicitly implement React Server Function endpoints may be vulnerable if they support React Server Components, as the vulnerability affects default configurations.
Attack Vector:
Impact:
References:
Severity: CRITICAL (CVSS 10.0)
Affected Package: next
Vulnerability Type: Insecure Deserialization (inherited from React RSC)
Description: A critical Remote Code Execution vulnerability in Next.js affects applications using the App Router with React Server Components. This vulnerability is the downstream manifestation of CVE-2025-55182, as Next.js inherits the flaw through its implementation of the React Flight protocol.