Back to blog

Blog Post

New offensive security research: Remote Code Execution (RCE) vulnerability in Next.js

Share on social

Jan 17, 2026

Lorem ipsum

Table of contents

Share on social

Join the newsletter
New offensive security research: Remote Code Execution (RCE) vulnerability in Next.js

[RCE Vulnerability Research]

To support customer testing and validation, we've added a reverse-engineered proof of concept to Assetnote. Our research team also published an open-source test, which is available on our GitHub.

Contact sales

An advisory has revealed a critical, unauthenticated Remote Code Execution (RCE) vulnerability in Next.js, rooted in React Server Components, which requires immediate patching. Given the severity of this issue, in addition to developing a high-fidelity check across our ASM platform, Assetnote, our Security Research team also published an open-source command-line tool for detecting CVE-2025-55182 and CVE-2025-66478 in Next.js applications using React Server components.

Communicating the critical risk: Executive summary

Next.js is a powerful web development framework that simplifies the process of building fast, interactive applications. If a bad actor was able to exploit this RCE vulnerability, they could take full control of your app, access and exfiltrate data, or use their access as a way to pivot into other systems and conduct disruptive attacks.

Searchlight Cyber's security research team constantly uncovers new vulnerabilities and feeds them directly into our platform, giving you early warnings on zero-days so you can mitigate them before attackers have the chance to exploit them.

Read the full advisory on our security research blog

About Assetnote

Searchlight Cyber's ASM solution, Assetnote, provides industry-leading attack surface management and adversarial exposure validation solutions, helping organizations identify and remediate security vulnerabilities before they can be exploited. Customers receive security alerts and recommended mitigations simultaneously with any disclosures made to third-party vendors. Visit our attack surface management page to learn more about our platform and the research we do.

Alex Blackman

Author

Alex Blackman

Head of Product Marketing at Searchlight Cyber

Alex Blackman leads product marketing at Searchlight Cyber, where he's responsible for taking the company's Preemptive Threat Exposure Management platform to market. Before joining Searchlight, Alex worked with global brands including Unilever and Allianz. He runs Searchlight's webinar programme and spends most of his time helping security teams understand why preemptive beats reactive and how that works in the Searchlight platform.

Related Blog Posts

September 16, 2026

How AI Is Collapsing Exploitation Timelines

September 15, 2026

Faster Leaked Credential Search with a rebuilt experience

September 10, 2026

Beacon: Searchlight Researchers Uncover JavaScript Sandbox Flaw Enabling RCE in Zendesk and Nuclei

September 3, 2026

Beacon: FulcrumSec Claims Responsibility for Manchester Airport Group Breach

September 1, 2026

Searchlight Threat + RST Cloud: Instant insights from 1,000s of threat reports

August 27, 2026

Beacon: North Korean Hackers Linked to Rust Supply Chain Attack

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient