PT-2025-50722 · Meta +1 · React +3

Published

2025-12-11

·

Updated

2026-01-28

·

CVE-2025-55183

CVSS v3.1
5.3
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions React versions 19.0.0 through 19.2.1 react-server-dom-parcel versions 19.0.0 through 19.2.1 react-server-dom-turbopack versions 19.0.0 through 19.2.1 react-server-dom-webpack versions 19.0.0 through 19.2.1
Description An information leak issue exists in React Server Components. A crafted HTTP request to a vulnerable Server Function can expose the source code of that function. Exploitation requires a Server Function that exposes a stringified argument. The issue may affect applications even without Server Functions. The vulnerability could potentially reveal business logic and assumptions.
Recommendations Update to a newer version of React to address this vulnerability.

Fix

Related Identifiers

CVE-2025-55183

Affected Products

React
React-Server-Dom-Parcel
React-Server-Dom-Turbopack
React-Server-Dom-Webpack