Critical React Server Components Vulnerability Exposes Apps to Unauthenticated Remote Code Execution
React Team discloses a critical vulnerability (CVE-2025-55182) in React Server Components that allows unauthenticated remote code execution. With a CVSS score of 10.0, the flaw affects multiple versions of react-server-dom packages and several popular frameworks, requiring immediate upgrades.