Watch Breakglass close an exploited flaw without taking booking offline
The hospital is fictional and its portal is a harmless twin; the flaw is a real entry from CISA's list; the "attack" is a benign marker request. Every card says which parts are live.
Meta React Server Components flaw on the patient portal: contained without taking patient routes offline
CVE-2025-55182, Meta React Server Components (CISA KEV). The fixed version can't be installed today. Breakglass proves the flaw matters here, applies one reversible control, and proves patients can still book.
fig. 1 Evidence · two factors before any action
Could it happen here? Is it happening?fig. 4 Verification · risk down, care up
ClickHouse, per 10 sVerification runs after a control is applied: zero unblocked requests on the risky route, and a scripted patient still signs in and books.
fig. 7 Attack timeline · ClickHouse
UTC · from the request log and this incident's eventsPeak 2 hostile requests per 10 s to /portal/messages.
| Time | What happened | Source |
|---|---|---|
| 04:23:20 UTC | First hostile request in the recorded window 2 non-patient requests to /portal/messages in that 10 s (the window starts 60 s before the incident opened) | ClickHouse |
| 04:24:17 UTC | Advisory ingested CVE-2025-55182 entered the advisory stream (replay of a real KEV entry) | MongoDB |
fig. 0 The advisory
What the government's list saysMeta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.
- Added to KEV
- Dec 5, 2025
- Federal due date
- Dec 12, 2025 (7 days after listing)
- EPSS
- 99.8% chance of exploitation in 30 days · top 0.5% (2026-10-04)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Timeline
UTC- Advisory ingested
- 04:24:17 UTC
- Trigger
- Replay of a real KEV entry into the advisory stream
- Agent runtime
- Hosted and run in Guild · Guild's record · strategy: containment-first
- Opened
- 04:24:17 UTC
- Closed
- —
Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.