Deserialization of untrusted data in React - CVE-2025-55182
Published: December 3, 2025 / Updated: June 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data passed to React Server Function endpoints. A remote non-authenticated attacker can send a specially crafted HTTP request to the React server components and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Rhapsody Systems Engineering
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Maximo Application Suite - Edge Data Collector
MANTA Automated Data Lineage for IBM Cloud Pak for Data
QRadar Suite
IBM Security QRadar Analyst Workflow
QRadar User Behavior Analytics
IBM Concert Software
How to mitigate CVE-2025-55182
Rhapsody Systems Engineering - update to 1.5.3
QRadar User Behavior Analytics - update to 5.0.3
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3.1
Maximo Application Suite - Edge Data Collector - update to 8.11.24
IBM Concert Software - update to 2.1.0 patch03
IBM Security QRadar Analyst Workflow - update to 3.0.1
MANTA Automated Data Lineage for IBM Cloud Pak for Data - update to 5.3.1
Links to Public Exploits and PoC-codes
- Exploit #12776 - CVE-2025-55182 (PoC exploit for CVE-2025-55182 (React2Shell) — Pre-auth RCE in React Server Components | CVSS 10.0) (June 23, 2026)
- Exploit #12596 - PoC-CVE-2025-55182 (CVE-2025-55182 (React2Shell) PoC: Unauthenticated RCE affecting React 19.x and Next.js < 15.1.4. Exploits vulnerabilities in the RSC Flight protocol.) (April 17, 2026)
- Exploit #12541 - CVE-2025-55182_RCE_Exploit (REC Exploit is a Python-based security testing tool that automates detection of potential RCE conditions in web applications under authorized environments. It sends crafted POST requests to targets, analyzes server responses fo (April 1, 2026)
- Exploit #12411 - exploit-cve-2025 () (February 13, 2026)
- Exploit #12263 - vulnerable-next-js-poc (January 9, 2026)
- Exploit #12240 - nextploiter (NextJS exploiter for CVE-2025-55182 and more. ) (January 4, 2026)
- Exploit #12185 - Unauthenticated RCE in React and Next.js (December 9, 2025)
- Exploit #12179 - rust-flight (High-performance exploitation engine for CVE-2025-55182 (React Server Components RCE)) (December 4, 2025)
- Exploit #12178 - CVE-2025-55182-poc (December 4, 2025)
- Exploit #12177 - react2shell-scanner (December 4, 2025)
- Exploit #12175 - CVE-2025-55182 (December 4, 2025)
- Exploit #12174 - CVE-2025-55182-exploit (December 4, 2025)
External References
Related Security Bulletins
- Remote code execution in React
- IBM Edge Data Collector update for React Server Components
- IBM Rhapsody Systems Engineering update for React Server Components
- MANTA Automated Data Lineage for IBM Cloud Pak for Data update for React Server Components
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow for IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- IBM Concert Software update for React Server Components
- IBM QRadar Suite Software update for React Server Components
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for React Server Components