Information Leak in React Server Components by Meta Platforms
CVE-2025-55183

5.3MEDIUM

What is CVE-2025-55183?

An information leak vulnerability has been identified in React Server Components, allowing crafted HTTP requests to potentially expose the source code of sensitive Server Functions. This risk arises when specific configurations are employed, and conditions are met that make it possible to retrieve stringified arguments. Affected versions include several releases from 19.0.0 through 19.2.1 across related packages. Developers should review their configurations and take necessary precautions to mitigate this exposure risk.

Affected Version(s)

react-server-dom-parcel 19.0.0 <= 19.0.1

react-server-dom-parcel 19.1.0 <= 19.1.2

react-server-dom-parcel 19.2.0 <= 19.2.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55183 : Information Leak in React Server Components by Meta Platforms