Next.js Framework React Server Components Source Code Exposure (CVE-2025-55183)

medium Nessus Plugin ID 279413

Synopsis

The Next.js Framework on the remote host is affected by a source code exposure vulnerability.

Description

The Next.js Framework on the remote host is affected by a source code exposure vulnerability:

- An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages:
react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument. (CVE-2025-55183)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Next.js Framework version 15.0.7, 15.1.11, 15.2.8, 15.3.8, 15.4.10, 15.5.9, 15.6.0-canary.60, 16.0.10, 16.1.0-canary.19 or later.

See Also

https://nextjs.org/blog/security-update-2025-12-11

Plugin Details

Severity: Medium

ID: 279413

File Name: nextjs_framework_CVE-2025-55183.nasl

Version: 1.1

Type: local

Agent: windows, macosx, unix

Family: Misc.

Published: 12/19/2025

Updated: 12/19/2025

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.5

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2025-55183

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Vulnerability Information

CPE: cpe:/a:vercel:next.js

Required KB Items: Host/nodejs/modules/enumerated

Patch Publication Date: 12/11/2025

Vulnerability Publication Date: 12/11/2025

Reference Information

CVE: CVE-2025-55183

IAVA: 2025-A-0929