
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67489 is a critical Remote Code Execution (RCE) vulnerability in @vitejs/plugin-rsc, the React Server Components (RSC) support plugin for Vite. It affects versions 0.5.5 and below, allowing unauthenticated attackers with network access to the development server to execute arbitrary JavaScript code with Node.js privileges via unsafe dynamic imports in server function APIs. The vulnerability was published on December 8, 2025, and patched in version 0.5.6. It carries a CVSS v3.1 base score of 9.8 (Critical) (Github Advisory, Security Advisory).
The root cause is improper control of code generation (CWE-94): during development, the plugin's setRequireModule loader uses an unvalidated dynamic import() call to load server function modules identified by attacker-controlled IDs from HTTP request headers (x-rsc-action) and body payloads processed by loadServerAction, decodeReply, and decodeAction APIs. Because no allowlist or validation was applied to the module identifier, an attacker can supply a data: URL (e.g., data:text/javascript,<payload>#) as the module ID, causing Node.js to evaluate arbitrary JavaScript. The fix (commit fe634b5) introduces a rsc:reference-validation Vite plugin that validates reference IDs against known server/client reference maps before allowing the dynamic import to proceed (Security Advisory, Patch Commit).
Successful exploitation grants an attacker full Node.js process privileges on the development server, enabling arbitrary file read and write, exfiltration of sensitive data such as source code, environment variables, and credentials, and potential lateral movement to other internal services reachable from the development host. The risk is significantly elevated when the Vite server is started with vite --host, which exposes it on all network interfaces and makes it reachable beyond localhost. All three CIA triad dimensions are rated High (Github Advisory).
A public proof-of-concept exploit is available via the GitHub Security Advisory and a live StackBlitz demo, demonstrating exploitation with a simple Node.js script requiring no authentication or special privileges. No evidence of in-the-wild exploitation has been reported as of the advisory date. The EPSS score is approximately 0.362% (59th percentile), indicating a moderate near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Security Advisory).
@vitejs/plugin-rsc ≤ 0.5.5 that are network-accessible, particularly those started with vite --host (default port 5173). Scan for open port 5173 on target networks using tools like Nmap or Shodan.http://<target>:5173/_.rsc, by sending a benign GET or OPTIONS request.data: URL module as the server function reference ID:const payload = {
0: ["$F1"],
1: { id: "data:text/javascript,<MALICIOUS_CODE># " },
};x-rsc-action header can also carry a data: URL payload for a second injection vector:POST /_.rsc HTTP/1.1
Host: <target>:5173
x-rsc-action: data:text/javascript,<MALICIOUS_CODE>#
Content-Type: multipart/form-data; boundary=...loadServerAction or decodeReply API passes the attacker-controlled ID to an unvalidated import() call, causing Node.js to evaluate the data: URL as a JavaScript module with full server privileges — enabling file exfiltration, credential theft, or reverse shell establishment (Security Advisory).<host>:5173/_.rsc from external or non-developer IP addresses; requests containing data:text/javascript strings in the x-rsc-action header or multipart form body fields.data: URL modules; Node.js error or console output containing attacker-injected strings (e.g., REMOTE CODE EXECUTION).curl, wget, bash, sh, python) performing outbound network connections or file operations./tmp created by the Vite server process; unexpected .env file access or exfiltration artifacts.Upgrade @vitejs/plugin-rsc to version 0.5.6 or later, which introduces reference ID validation before dynamic imports are executed (Security Advisory, Patch Commit). As immediate workarounds prior to patching: avoid using vite --host to prevent exposing the development server beyond localhost; restrict network access to development environments via firewall rules or network segmentation; and review and rotate any credentials or secrets that may have been accessible to the development server process.
The vulnerability was reported by security researchers xdavidhu and Ry0taK and published by maintainer hi-ogawa on December 8, 2025. It was noted in PoC-tracking digests for the weeks of December 15 and December 22, 2025, and included in a CISA vulnerability bulletin (SB25-349). Red Hat also tracked the CVE. Community discussion was observed on Bluesky and Mastodon/CIRCL vulnerability lookup channels shortly after disclosure (Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."