
Itamar Sher
December 4, 2025
CVSS 10.0 CVE in React & Next.js: How You Can Stay Safe
On December 3rd, CVE-2025-55182 was published by CISA. This CVSS 10.0 vulnerability allows unauthenticated remote code execution, where a threat actor can exploit a flaw in React’s process to decode payloads sent to React Server Function endpoints. See how the vulnerability works and how Seal can help in our latest blog.