CVE-2025-67779 | Meta react-server-dom-parcel up to 19.0.2/19.1.3/19.2.2 React Server deserialization (Nessus ID 278532 / WID-SEC-2025-2835)
A vulnerability, which was classified as problematic, has been found in Meta react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack up to 19.0.2/19.1.3/19.2.2. Impacted is an unknown function of the component React Server Component. Performing manipulation results in deserialization.
This vulnerability is cataloged as CVE-2025-67779. It is possible to initiate the attack remotely. There is no exploit available.