Skip to content

Comments

fix: CVE-2025-55182 Critical RCE vulnerabilty#13175

Merged
bluebill1049 merged 2 commits intoreact-hook-form:masterfrom
PierreCrb:master
Dec 3, 2025
Merged

fix: CVE-2025-55182 Critical RCE vulnerabilty#13175
bluebill1049 merged 2 commits intoreact-hook-form:masterfrom
PierreCrb:master

Conversation

@PierreCrb
Copy link
Contributor

🔒 Security Fix: Patch for CVE-2025-55182 (React Server Components RCE)

This PR updates the project's React dependencies to address CVE-2025-55182, a critical pre-authentication remote code execution vulnerability affecting React Server Components.

The vulnerability impacts React versions 19.0.0 → 19.2.0 due to unsafe deserialization of payloads sent to Server Function endpoints.
Even projects that do not explicitly use Server Functions may still be exposed if they support React Server Components.

✔️ Changes

  • react: 19.2.019.2.1
  • react-dom: 19.2.019.2.1

These versions include the official security patch released by the React team on December 3, 2025.

✔️ Why this is important

The vulnerability is rated CVSS 10.0 (Critical) and allows an unauthenticated attacker to achieve remote code execution on servers using affected React packages.
Upgrading to the patched versions fully mitigates the issue.

Feel free to let me know if any adjustments or additional updates are needed.

@bluebill1049 bluebill1049 merged commit 602f399 into react-hook-form:master Dec 3, 2025
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants