Breakglass
Incidents
← IncidentsConnecting…
INC-0011·Mercy Valley Community Hospital·Patient portalReplay of a real KEV entrySimulated hospitalFault injected: stale inventory

Meta React Server Components flaw on the patient portal: contained after one automatic rollback; the first control broke booking, and Breakglass undid it by itself

CVE-2025-55182, Meta React Server Components (CISA KEV). The fixed version can't be installed today. Breakglass proved the flaw matters here and applied a reversible control; that control broke a patient journey, so Breakglass rolled it back by itself, applied the next one, and proved patients can book again.

✓ CONTAINED
1:03
exposure closed, from ingest to verified
federal due window: 7 days

fig. 1 Evidence · two factors before any action

Could it happen here? Is it happening?
✓The code reaches the flawed partSemgrep · SEMGREP CE
targets/mercy-portal/app/appointments/actions.ts:6 React Server Function `bookAppointment` is exported from a "use server" module. Requests to it are decoded by react-server-dom-*; CVE-2025-55182 (CISA KEV) is a flaw in that decoding for affected versions.
export async function bookAppointment(slotId: string) {
  const session = await requireSession();
  return schedule.book(session.patientId, slotId);
targets/mercy-portal/app/appointments/page.tsx:10 A route component invokes server function `bookAppointment`, so the endpoint that decodes its payload is reachable from that route.
{s.label} <button onClick={() => bookAppointment(s.id)}>Book</button>
4 more findings
targets/mercy-portal/app/billpay/actions.ts:6 React Server Function `payBalance` is exported from a "use server" module. Requests to it are decoded by react-server-dom-*; CVE-2025-55182 (CISA KEV) is a flaw in that decoding for affected versions.
targets/mercy-portal/app/billpay/page.tsx:4 A route component invokes server function `payBalance`, so the endpoint that decodes its payload is reachable from that route.
targets/mercy-portal/app/messages/actions.ts:10 React Server Function `sendCareTeamMessage` is exported from a "use server" module. Requests to it are decoded by react-server-dom-*; CVE-2025-55182 (CISA KEV) is a flaw in that decoding for affected versions.
targets/mercy-portal/app/messages/page.tsx:4 A route component invokes server function `sendCareTeamMessage`, so the endpoint that decodes its payload is reachable from that route.
rule bg-rsc-server-action-defined · direct dependency react-server-dom-webpack 19.1.0
Custom rules over the portal source: server functions defined and invoked from 3 route(s). Semgrep Community Edition (no account); the affected version comes from the lockfile and OSV.
✓That route is being hit right nowClickHouse · CLICKHOUSE CLOUD
209 requests on 3 candidate routes in the last 5 min, 178 unblocked · 12 journey, 147 patient, 50 marker
ClickHouse decision: /portal/messages · 80 requests in 5 min, 49 unblocked, hostile traffic on this route → exposed route → BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
The agent's query
SELECT route_id, client_kind, count() AS total, countIf(blocked = 0) AS unblocked
FROM bg.edge_requests
WHERE site = 'managed' AND route_id IN ('portal.book', 'portal.messages', 'portal.billpay')
  AND ts >= now() - INTERVAL 300 SECOND
GROUP BY route_id, client_kind
✓ BOTH FACTORS: MAY ACTStatic evidence alone, or traffic alone, never triggers a change.

fig. 3 Decision · one control ID from the catalog

guild:code~breakglass-decision · structured output
BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
Refuse server-action requests that carry no signed-in session
  • Semgrep shows the vulnerable server actions are reachable from all three candidate routes.
  • ClickHouse live traffic shows hostile (marker) requests on /portal/messages, confirming real-world probing/exploitation.
  • Breaking policy forbids taking the entire portal offline, and disable-messages or body-limits would not protect booking if targeted.
  • Requiring a signed-in session blocks all unauthenticated exploitation with minimal disruption to legitimate patient traffic.
Considered and not chosen (3)
  • BG-CTL-PORTAL-DISABLE-MESSAGES Only disables messaging, but booking is vulnerable too.
  • BG-CTL-PORTAL-ACTION-BODY-LIMIT Too narrow; attacker could exploit via small payloads on vulnerable paths.
  • BG-CTL-PORTAL-BLOCK-ACTIONS-EXCEPT-BOOKING Blocks more patient functionality than needed; advisory says unauthenticated risk is primary.
reversibleblocking ruletouches no critical routepolicy: ALLOWconfidence 0.97

fig. 6 Controls applied

Every change, and every undo
ControlAppliedOutcome
BG-CTL-PORTAL-BLOCK-ALL-ACTIONS Fault injected04:30:04 UTCreverted
patient journey failed at Book
BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS04:30:24 UTCcontained
Exposure 0 and the patient journey passed.

fig. 4 Verification · risk down, care up

ClickHouse, per 10 s
probes that got through to /portal/messages, per 10 s
2004:28:4004:30:40applied (reverted)reverted → control applied0
patient journeys passing, % (one every 30 s; held between runs)
100004:28:4004:30:40applied (reverted)reverted → control applied100%
Sign in✓ 101 ms
jordan.lee → /portal
Find a slot✓ 12 ms
8 slots listed
Book✓ 62 ms
Next-Action: book → 200
Confirm✓ 1 ms
Booked · MV-BL7G
✓ EXPOSURE 0 UNBLOCKED / 20s✓ PATIENT JOURNEY · PLAYWRIGHT✓ CRITICAL ROUTES 0 × 5xx
fig. 5Agent trace · hosted and run in Guild 01a10a53-2188-351a-0000-fb523976c641open in Guild ↗Guild's record →every tool call, logged
0100:00.1triggeradvisory.insert CVE-2025-55182 entered the advisory stream (REPLAY) → session started
0200:00.1toolinventory.match portal · react-server-dom-webpack 19.1.0 implements React Server Components
0300:00.6triggerguild.session Guild session 01a10a53-2188-351a-0000-fb523976c641 started for code~breakglass-decision
1900:04.0guildguild.llm model call · gpt-4.1 (openai)
2000:05.2guildguild.llm model asked for breakglass_incident_context, breakglass_inventory_match
2100:05.7guildguild.tool tool call (incident_id=INC-0011)
2200:06.0guildguild.tool tool call (incident_id=INC-0011)
0400:06.5toolosv.query react-server-dom-webpack@19.1.0: affected (GHSA-fv66-9v8q-g76r)
2300:07.3guildguild.llm model call · gpt-4.1 (openai)
2400:08.2guildguild.llm model asked for breakglass_clickhouse_route_traffic, breakglass_semgrep_reachability
2500:08.6guildguild.tool tool call (incident_id=INC-0011)
2600:08.8guildguild.tool tool call (incident_id=INC-0011)
0500:09.3toolclickhouse.route_traffic 209 requests on 3 candidate route(s) in 5 min · hostile on portal.messages
0600:09.3toolsemgrep.reachability reachable · 6 finding(s) · routes portal.book, portal.billpay, portal.messages
2700:10.0guildguild.llm model call · gpt-4.1 (openai)
2800:10.7guildguild.llm model asked for breakglass_catalog_controls
2900:11.1guildguild.tool tool call (incident_id=INC-0011)
0700:11.6toolcatalog.list 4 of 7 controls eligible for portal · ranker's first: BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
3000:12.4guildguild.llm model call · gpt-4.1 (openai)
3100:13.1guildguild.llm model asked for breakglass_services_shutdown
3200:13.6guildguild.tool tool call (asset_id=portal)
3400:14.0guildguild.policy DENIED {'error': 'Forbidden', 'message': "Access to 'services_shutdown' is not permitted for this integration. Ask a workspace admin to update credential policies."}
3500:14.7guildguild.llm model call · gpt-4.1 (openai)
3600:15.7guildguild.llm model asked for breakglass_human_approval
3700:17.1guildguild.tool tool call (incident_id=INC-0011, summary=Tried to shut down the patient portal for critical RCE (CVE-)
0800:17.6approvalapproval.call not placed (disabled): Approval calls are switched off in Settings (live calls cost money). The denial stands; nothing drastic happens without a human.
3800:18.6guildguild.llm model call · gpt-4.1 (openai)
3900:20.6guildguild.llm model asked for breakglass_submit_decision
4000:21.1guildguild.tool tool call (alternatives=[{'control_id': 'BG-CTL-PORTAL-DISABLE-MESSAGES', 'why_not':, confidence=0.97, control_id=BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS, incident_id=INC-0011, reasons=['Semgrep shows the vulnerable server actions are reachable )
0900:21.5policygate.check ALLOWED BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS: all checks passed
1000:21.6llmdecide guild:code~breakglass-decision → BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS (confidence 0.97, 0 turns)
1100:21.8tooledge.apply BG-CTL-PORTAL-BLOCK-ALL-ACTIONS → ALLOWED by credential policy (allow-apply-catalog) · FAULT INJECTED: stale inventory said this was safe
4100:22.4guildguild.llm model call · gpt-4.1 (openai)
4200:23.5guildguild.reply BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
4300:24.0guildguild.done BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
1200:42.0verifyexposure 0 unblocked of 3 hostile requests in 20 s on portal.book, portal.messages
1300:42.0verifyjourney FAILED Sign in ✓ → Find a slot ✓ → Book ✕ (PLAYWRIGHT, 0.2 s)
1400:42.2revertedge.revert BG-CTL-PORTAL-BLOCK-ALL-ACTIONS reverted (patient journey failed at Book); failure recorded against the control
1500:42.5tooledge.apply BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS → ALLOWED by credential policy (allow-apply-catalog)
1601:02.6verifyexposure 0 unblocked of 3 hostile requests in 20 s on portal.book, portal.messages
1701:02.7verifyjourney Sign in ✓ → Find a slot ✓ → Book ✓ → Confirm ✓ (PLAYWRIGHT, 0.2 s)
1801:03.0statecontained exposure clock stopped at 1:03 · Refuse server-action requests that carry no signed-in session · watch armed
3303:47.3policyedge.shutdown(portal) DENIED by Guild's credential policy · services_shutdown
Watch retiredAny unblocked non-patient request to /portal/messages reopens INC-0011W-0010

fig. 7 Attack timeline · ClickHouse

UTC · from the request log and this incident's events

Peak 2 hostile requests per 10 s to /portal/messages · 3 blocked after the control.

TimeWhat happenedSource
04:28:40 UTCFirst hostile request in the recorded window
1 non-patient request to /portal/messages in that 10 s (the window starts 60 s before the incident opened)
ClickHouse
04:29:42 UTCAdvisory ingested
CVE-2025-55182 entered the advisory stream (replay of a real KEV entry)
MongoDB
04:29:51 UTCEvidence query
209 requests on 3 candidate route(s) in 5 min · hostile on portal.messages
ClickHouse
04:29:56 UTCShutdown denied
BG-CTL-PORTAL-SHUTDOWN refused (Guild's own time)
Guild credential policy
04:30:04 UTCToo-broad control applied
BG-CTL-PORTAL-BLOCK-ALL-ACTIONS (fault injected: a stale inventory let it through)
edge
04:30:24 UTCControl rolled back
BG-CTL-PORTAL-BLOCK-ALL-ACTIONS: the patient journey failed
edge + Playwright
04:30:24 UTCControl applied
BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
edge
04:30:30 UTCFirst 10 s with nothing getting through
2 hostile requests blocked, 0 through
ClickHouse
04:30:44 UTCVerified close
exposure 0 unblocked · patient journey passed · 0 × 5xx on critical routes
ClickHouse + Playwright

fig. 0 The advisory

What the government's list says
CVE-2025-55182Replay of a real KEV entryRansomware use: known
Meta React Server Components Remote Code Execution Vulnerability

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

Added to KEV
Dec 5, 2025
Federal due date
Dec 12, 2025 (7 days after listing)
EPSS
99.8% chance of exploitation in 30 days · top 0.5% (2026-10-04)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Timeline

UTC
Advisory ingested
04:29:42 UTC
Trigger
Replay of a real KEV entry into the advisory stream
Agent runtime
Hosted and run in Guild · Guild's record · strategy: containment-first
Opened
04:29:42 UTC
Closed
04:30:45 UTC

Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.