Next.js & React vulnerability will break the internet

Next.js & React vulnerability will break the internet

🎙 John Hammond 👥 2.2M 📅 December 5, 2025 ⏱ 11 min 👁 146K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

React Server ComponentsRemote Code ExecutionCVE-2025-55182CVE-2025-66478Next.js

Summary

John Hammond discusses the critical security vulnerabilities discovered in React and Next.js, specifically CVE-2025-55182 and CVE-2025-66478. These are unauthenticated remote code execution vulnerabilities with a CVSS score of 10.0, affecting React versions 19.0, 19.1.0, 19.1.1, and 19.2.0, and Next.js versions using the App Router. The vulnerability originates in React Server Components and the React Flight protocol, allowing attackers to craft malicious requests that can execute arbitrary code on the server. Hammond demonstrates a proof-of-concept exploit using a simple calculator command, and explains the technical details, including the use of prototype pollution and thenable objects. He emphasizes the urgency to patch, noting that a large percentage of cloud environments are exposed. The video also mentions the discovery by Lachlan Davidson, the release of proof-of-concept code by researchers like Moritz Samp and Maple3142, and the availability of scanners and detection tools. Hammond provides links to official advisories, GitHub repositories, and blog posts for further information. He concludes by warning that the vulnerability is likely to be widely exploited and urges viewers to update their software immediately.

174 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable information about a critical security vulnerability, including a live demonstration of the exploit. The argumentation is clear and emphasizes the severity and urgency of patching. However, the creator admits limited expertise in front-end technologies, which may affect the depth of technical explanation. The video relies on external sources and acknowledges the work of researchers, adding credibility. The demonstration is effective in showing the real-world impact, and the call to action to patch is well-supported.

Scientific Rigor, Source Quality, Title Accuracy

The video references multiple official sources, including React’s security advisory, CVE records, Next.js blog, and research from Wiz and SLCyber. The sources are credible and directly related to the vulnerabilities. The title accurately reflects the content, and the video does not misrepresent the severity. The creator provides links to all sources in the description, allowing viewers to verify the information. The explanation of the technical details is somewhat simplified and may contain inaccuracies, but the overall information is reliable.

172 words

Title / Content Match

The title accurately reflects the content, which discusses a critical vulnerability in React and Next.js that could have widespread impact.

Quality & Reliability

7/10

The video provides a clear overview of the critical React/Next.js vulnerabilities (CVE-2025-55182 and CVE-2025-66478), including a demonstration of a proof-of-concept exploit. The creator admits limited expertise in front-end development and relies on external sources, but the information is accurate and well-referenced. The explanation of the technical details is somewhat superficial and may contain inaccuracies, but the overall guidance to patch is sound.

Key Moments

Cited Sources

Concurring Sources

  • Wiz blog post — Confirms the severity and impact of the vulnerability.
  • SLCyber research — Provides detection mechanisms and confirms the exploitability.

External References

Contribution & Novelties

The video provides a timely and accessible overview of a critical vulnerability, including a live demonstration of the exploit. It aggregates information from multiple sources and highlights the severity and urgency. The creator’s perspective as a security educator adds value for viewers unfamiliar with the technical details.

Pour aller plus loin :

  • React Server Components — Official React blog post explaining the architecture.
  • Prototype pollution — PortSwigger article on prototype pollution, a key concept in the exploit.
  • Remote Code Execution — OWASP page on code injection and RCE.

88 words

Radar Profile

The radar profile shows a balanced performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the video's comprehensive coverage. The technical depth is moderate, suitable for a general audience, while reliability is solid due to the use of official sources.

Reliability 7/10

💬 The comments are predominantly positive and humorous, with viewers appreciating the timely coverage and the demonstration. Some express concern about the widespread impact, while others joke about the vulnerability. Overall, the sentiment is engaged and appreciative.