Skip to content

fix: patch CVE-2025-55182 React Server Components RCE - #5

Open
joeldbirch wants to merge 2 commits into
ai-hero-dev:mainfrom
joeldbirch:fix/cve-2025-55182-clean
Open

fix: patch CVE-2025-55182 React Server Components RCE#5
joeldbirch wants to merge 2 commits into
ai-hero-dev:mainfrom
joeldbirch:fix/cve-2025-55182-clean

Conversation

@joeldbirch

Copy link
Copy Markdown

Summary

  • Update next from 15.5.4 → 15.5.7
  • Update react from 19.1.0 → 19.1.2
  • Update react-dom from 19.1.0 → 19.1.2

Security

CVE-2025-55182 is a critical (CVSS 10.0) remote code execution vulnerability in React Server Components that is being actively exploited in the wild.

Reference: https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

🤖 Generated with Claude Code

joeldbirch and others added 2 commits December 12, 2025 10:30
Update to patched versions:
- next: 15.5.4 → 15.5.7
- react: 19.1.0 → 19.1.2
- react-dom: 19.1.0 → 19.1.2

CVE-2025-55182 is a critical (CVSS 10.0) remote code execution
vulnerability in React Server Components being actively exploited.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant