Meta React Server Components flaw on the patient portal: contained after one automatic rollback; the first control broke booking, and Breakglass undid it by itself
CVE-2025-55182, Meta React Server Components (CISA KEV). The fixed version can't be installed today. Breakglass proved the flaw matters here and applied a reversible control; that control broke a patient journey, so Breakglass rolled it back by itself, applied the next one, and proved patients can book again.
fig. 1 Evidence · two factors before any action
Could it happen here? Is it happening?fig. 2 Credential policy
Guild decides, not the modelguild:services_shutdown:DENY matched at Guild's credential proxy. DENY wins: Guild's credential proxy refused 'services_shutdown' before any request left Guild (Access to 'services_shutdown' is not permitted for this integration.). The hospital's playbook says strongest containment first, so the agent asked for BG-CTL-PORTAL-SHUTDOWN; the policy refused and its credential was never used for it.security_event · services_shutdown · DENY · FORBIDDEN (runtime_error) · 04:29:56 UTCfig. 3 Decision · one control ID from the catalog
guild:code~breakglass-decision · structured output- Semgrep shows the vulnerable server actions are reachable from all three candidate routes.
- ClickHouse live traffic shows hostile (marker) requests on /portal/messages, confirming real-world probing/exploitation.
- Breaking policy forbids taking the entire portal offline, and disable-messages or body-limits would not protect booking if targeted.
- Requiring a signed-in session blocks all unauthenticated exploitation with minimal disruption to legitimate patient traffic.
Considered and not chosen (3)
BG-CTL-PORTAL-DISABLE-MESSAGESOnly disables messaging, but booking is vulnerable too.BG-CTL-PORTAL-ACTION-BODY-LIMITToo narrow; attacker could exploit via small payloads on vulnerable paths.BG-CTL-PORTAL-BLOCK-ACTIONS-EXCEPT-BOOKINGBlocks more patient functionality than needed; advisory says unauthenticated risk is primary.
fig. 6 Controls applied
Every change, and every undo| Control | Applied | Outcome |
|---|---|---|
| BG-CTL-PORTAL-BLOCK-ALL-ACTIONS Fault injected | 04:30:04 UTC | reverted patient journey failed at Book |
| BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS | 04:30:24 UTC | contained Exposure 0 and the patient journey passed. |
fig. 4 Verification · risk down, care up
ClickHouse, per 10 sfig. 7 Attack timeline · ClickHouse
UTC · from the request log and this incident's eventsPeak 2 hostile requests per 10 s to /portal/messages · 3 blocked after the control.
| Time | What happened | Source |
|---|---|---|
| 04:28:40 UTC | First hostile request in the recorded window 1 non-patient request to /portal/messages in that 10 s (the window starts 60 s before the incident opened) | ClickHouse |
| 04:29:42 UTC | Advisory ingested CVE-2025-55182 entered the advisory stream (replay of a real KEV entry) | MongoDB |
| 04:29:51 UTC | Evidence query 209 requests on 3 candidate route(s) in 5 min · hostile on portal.messages | ClickHouse |
| 04:29:56 UTC | Shutdown denied BG-CTL-PORTAL-SHUTDOWN refused (Guild's own time) | Guild credential policy |
| 04:30:04 UTC | Too-broad control applied BG-CTL-PORTAL-BLOCK-ALL-ACTIONS (fault injected: a stale inventory let it through) | edge |
| 04:30:24 UTC | Control rolled back BG-CTL-PORTAL-BLOCK-ALL-ACTIONS: the patient journey failed | edge + Playwright |
| 04:30:24 UTC | Control applied BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS | edge |
| 04:30:30 UTC | First 10 s with nothing getting through 2 hostile requests blocked, 0 through | ClickHouse |
| 04:30:44 UTC | Verified close exposure 0 unblocked · patient journey passed · 0 × 5xx on critical routes | ClickHouse + Playwright |
fig. 0 The advisory
What the government's list saysMeta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.
- Added to KEV
- Dec 5, 2025
- Federal due date
- Dec 12, 2025 (7 days after listing)
- EPSS
- 99.8% chance of exploitation in 30 days · top 0.5% (2026-10-04)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Timeline
UTC- Advisory ingested
- 04:29:42 UTC
- Trigger
- Replay of a real KEV entry into the advisory stream
- Agent runtime
- Hosted and run in Guild · Guild's record · strategy: containment-first
- Opened
- 04:29:42 UTC
- Closed
- 04:30:45 UTC
Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.