SA-2025-001|
December 8, 2025
React Server Components Remote Code Execution
CVE-2025-55182
CriticalRemediated
Critical vulnerability in React Server Components allowing unauthenticated remote code execution.
Our Response
- Upon review of the advisory published December 3, 2025, our security team assessed and confirmed there was no exposure through affected dependencies.
- We can confirm, that we still upgraded to patched framework version (Next.js 15.5.7) the same day.
- Verified system functionality and deployed the fix to all environments.
- We also performed a comprehensive security assessment to verify no exploitation prior to patching.