CVE-2025-55183 is an information leak vulnerability affecting specific configurations of React Server Components (versions 19.0.0-19.2.1), including packages like react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack, impacting products such as Facebook React and Vercel Next.js. A specially crafted HTTP request can cause a vulnerable Server Function to return its source code if it explicitly or implicitly exposes a stringified argument. Rated Medium (CVSS 5.3), this vulnerability has a low attack complexity and requires no user interaction or privileges, potentially leading to unauthorized information disclosure. While not yet in CISA's KEV catalog or having public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion (273 mentions) and media coverage, indicating high awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.0.0, < 15.0.7CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* | ||
>= 15.1.0, < 15.1.11CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* | ||
>= 15.2.0, < 15.2.8CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* | ||
>= 15.3.0, < 15.3.8CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* | ||
>= 15.4.0, < 15.4.10CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.