Meta React Server Components flaw on the patient portal: contained by Breakglass, then a test tap from a headless phone browser approved taking it offline on the phone
CVE-2025-55182, Meta React Server Components (CISA KEV). Breakglass contained it with one reversible control and proved patients could still book. The playbook's shutdown was refused by the credential policy and handed to IT on-call; a test tap (headless phone browser, not a person) approved it on the phone page, so the asset was then taken offline under the operator credential.
fig. 1 Evidence · two factors before any action
Could it happen here? Is it happening?fig. 2 Credential policy
Guild decides, not the modelguild:services_shutdown:DENY matched at Guild's credential proxy. DENY wins: Guild's credential proxy refused 'services_shutdown' before any request left Guild (Access to 'services_shutdown' is not permitted for this integration.). The hospital's playbook says strongest containment first, so the agent asked for BG-CTL-PORTAL-SHUTDOWN; the policy refused and its credential was never used for it.security_event · services_shutdown · DENY · FORBIDDEN (runtime_error) · 05:16:15 UTCfig. 3 Decision · one control ID from the catalog
guild:code~breakglass-decision · structured output- Semgrep confirms all three portal server-action routes are reachable via vulnerable React server functions.
- ClickHouse shows live hostile traffic (marker clients) on /portal/messages, which is reachable and not required for core patient care.
- The catalog's narrowest eligible control covering the exploited unauthenticated route is BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS, blocking unauthenticated server-action requests everywhere, per advisory.
- Shut-down was denied by hospital policy, so this is the strongest reversible control with low blast radius.
Considered and not chosen (1)
BG-CTL-PORTAL-DISABLE-MESSAGESLower-ranked controls do not block unauthenticated traffic across all reachable routes: only BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS fully mitigates per advisory.
fig. 6 Controls applied
Every change, and every undo| Control | Applied | Outcome |
|---|---|---|
| BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS | 05:16:20 UTC | contained Exposure 0 and the patient journey passed. |
fig. 4 Verification · risk down, care up
ClickHouse, per 10 sfig. 7 Attack timeline · ClickHouse
UTC · from the request log and this incident's eventsPeak 2 hostile requests per 10 s to /portal/messages · 2 blocked after the control.
| Time | What happened | Source |
|---|---|---|
| 05:15:00 UTC | First hostile request in the recorded window 1 non-patient request to /portal/messages in that 10 s (the window starts 60 s before the incident opened) | ClickHouse |
| 05:15:59 UTC | Advisory ingested CVE-2025-55182 entered the advisory stream (replay of a real KEV entry) | MongoDB |
| 05:16:09 UTC | Evidence query 184 requests on 3 candidate route(s) in 5 min · hostile on portal.messages | ClickHouse |
| 05:16:15 UTC | Shutdown denied BG-CTL-PORTAL-SHUTDOWN refused (Guild's own time) | Guild credential policy |
| 05:16:20 UTC | Control applied BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS | edge |
| 05:16:30 UTC | First 10 s with nothing getting through 2 hostile requests blocked, 0 through | ClickHouse |
| 05:16:41 UTC | Verified close exposure 0 unblocked · patient journey passed · 0 × 5xx on critical routes | ClickHouse + Playwright |
fig. 0 The advisory
What the government's list saysMeta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.
- Added to KEV
- Dec 5, 2025
- Federal due date
- Dec 12, 2025 (7 days after listing)
- EPSS
- 99.8% chance of exploitation in 30 days · top 0.5% (2026-10-04)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Timeline
UTC- Advisory ingested
- 05:15:59 UTC
- Trigger
- Replay of a real KEV entry into the advisory stream
- Agent runtime
- Hosted and run in Guild · Guild's record · strategy: containment-first
- Opened
- 05:15:59 UTC
- Closed
- 05:16:41 UTC
Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.