KB-2362 Information about the React Server Components, including Next.js (React2Shell, CVE-2025-55182 & CVE-2025-66478)

Overview:

On 03-Dec-2025, two vulnerabilities were discovered related to the React Server Components that affect React 19 and the frameworks that use it, including Next.js. Applications using affected versions of the React Server Components implementation may process untrusted input in a way that allows an attacker to perform remote code execution.

Affected Components:

React Server components in React 19.x and Next.js 15.x/16.x with App Router

Appian has investigated these vulnerabilities and services, and determined that it is not impacted.

Additional Notes:

The following CVEs were released with additional information on the scope of the vulnerability:

  • CVE-2025-55182 - (A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0)
  • CVE-2025-66478 - (Next.js vulnerability, current rejected by NVD)

Supporting Documentation:

Affected Versions

This article applies to all supported versions of Appian.

Last reviewed: Dec 5, 2025

Related
Recommended