Breakglass
Incidents
Guided demo · Mercy Valley Community Hospital Simulated hospital

Watch Breakglass close an exploited flaw without taking booking offline

The hospital is fictional and its portal is a harmless twin; the flaw is a real entry from CISA's list; the "attack" is a benign marker request. Every card says which parts are live.

ProblemThe patch can't be installed today, and shutting the portal down stops patients booking.
SolutionProve it matters here, apply one reversible control, prove care still works.
Why it mattersThe exposure window closes in seconds, not days, without trading safety for uptime.
How it's usedPlay the recorded run here; live, replay and fault runs need the backend running.
00:00.0 / 01:04.9Replay · run recorded 2000-01-01
INC-0006·Mercy Valley Community Hospital·Patient portalReplay of a real KEV entrySimulated hospital

Meta React Server Components flaw on the patient portal: contained without taking patient routes offline

CVE-2025-55182, Meta React Server Components (CISA KEV). The fixed version can't be installed today. Breakglass proves the flaw matters here, applies one reversible control, and proves patients can still book.

● DETECTED
0:00
exposure open since ingest
federal due window: 7 days

fig. 1 Evidence · two factors before any action

Could it happen here? Is it happening?
…Checking reachability…Semgrep · SEMGREP CE
rule bg-rsc-server-action-defined · direct dependency react-server-dom-webpack 19.1.0 · 1.0 s
…Querying traffic…ClickHouse · CLICKHOUSE CLOUD
0 requests on 3 candidate routes in the last 5 min, 0 unblocked
– ONE FACTOR MISSING: NO CHANGEStatic evidence alone, or traffic alone, never triggers a change.

fig. 4 Verification · risk down, care up

ClickHouse, per 10 s
probes that got through to /portal/messages, per 10 s
1004:23:1004:24:100
patient journeys passing, % (one every 30 s; held between runs)
100004:23:1004:24:10100%

Verification runs after a control is applied: zero unblocked requests on the risky route, and a scripted patient still signs in and books.

fig. 5Agent trace · hosted and run in Guild 01a10a4e-2d19-351a-0000-0c9964a2dd41open in Guild ↗Guild's record →every tool call, logged
Waiting for the first event…

fig. 7 Attack timeline · ClickHouse

UTC · from the request log and this incident's events

Peak 2 hostile requests per 10 s to /portal/messages.

TimeWhat happenedSource
04:23:20 UTCFirst hostile request in the recorded window
2 non-patient requests to /portal/messages in that 10 s (the window starts 60 s before the incident opened)
ClickHouse
04:24:17 UTCAdvisory ingested
CVE-2025-55182 entered the advisory stream (replay of a real KEV entry)
MongoDB

fig. 0 The advisory

What the government's list says
CVE-2025-55182Replay of a real KEV entryRansomware use: known
Meta React Server Components Remote Code Execution Vulnerability

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

Added to KEV
Dec 5, 2025
Federal due date
Dec 12, 2025 (7 days after listing)
EPSS
99.8% chance of exploitation in 30 days · top 0.5% (2026-10-04)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Timeline

UTC
Advisory ingested
04:24:17 UTC
Trigger
Replay of a real KEV entry into the advisory stream
Agent runtime
Hosted and run in Guild · Guild's record · strategy: containment-first
Opened
04:24:17 UTC
Closed
—

Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.