CVE-2025-55183 | Meta react-server-dom-webpack up to 19.0.1/19.1.2/19.2.1 React Server deserialization (WID-SEC-2025-2835)
A vulnerability was found in Meta react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel up to 19.0.1/19.1.2/19.2.1. It has been declared as problematic. Impacted is an unknown function of the component React Server Component. Such manipulation leads to deserialization.
This vulnerability is listed as CVE-2025-55183. The attack may be performed from remote. There is no available exploit.