Breakglass
Incidents
← IncidentsConnecting…
INC-0012·Mercy Valley Community Hospital·Patient portalReplay of a real KEV entrySimulated hospital

Meta React Server Components flaw on the patient portal: contained by Breakglass, then a test tap from a headless phone browser approved taking it offline on the phone

CVE-2025-55182, Meta React Server Components (CISA KEV). Breakglass contained it with one reversible control and proved patients could still book. The playbook's shutdown was refused by the credential policy and handed to IT on-call; a test tap (headless phone browser, not a person) approved it on the phone page, so the asset was then taken offline under the operator credential.

✓ CONTAINED
0:41
exposure closed, from ingest to verified
federal due window: 7 days

fig. 1 Evidence · two factors before any action

Could it happen here? Is it happening?
✓The code reaches the flawed partSemgrep · SEMGREP CE
targets/mercy-portal/app/appointments/actions.ts:6 React Server Function `bookAppointment` is exported from a "use server" module. Requests to it are decoded by react-server-dom-*; CVE-2025-55182 (CISA KEV) is a flaw in that decoding for affected versions.
export async function bookAppointment(slotId: string) {
  const session = await requireSession();
  return schedule.book(session.patientId, slotId);
targets/mercy-portal/app/appointments/page.tsx:10 A route component invokes server function `bookAppointment`, so the endpoint that decodes its payload is reachable from that route.
{s.label} <button onClick={() => bookAppointment(s.id)}>Book</button>
4 more findings
targets/mercy-portal/app/billpay/actions.ts:6 React Server Function `payBalance` is exported from a "use server" module. Requests to it are decoded by react-server-dom-*; CVE-2025-55182 (CISA KEV) is a flaw in that decoding for affected versions.
targets/mercy-portal/app/billpay/page.tsx:4 A route component invokes server function `payBalance`, so the endpoint that decodes its payload is reachable from that route.
targets/mercy-portal/app/messages/actions.ts:10 React Server Function `sendCareTeamMessage` is exported from a "use server" module. Requests to it are decoded by react-server-dom-*; CVE-2025-55182 (CISA KEV) is a flaw in that decoding for affected versions.
targets/mercy-portal/app/messages/page.tsx:4 A route component invokes server function `sendCareTeamMessage`, so the endpoint that decodes its payload is reachable from that route.
rule bg-rsc-server-action-defined · direct dependency react-server-dom-webpack 19.1.0 · 1.3 s
Custom rules over the portal source: server functions defined and invoked from 3 route(s). Semgrep Community Edition (no account); the affected version comes from the lockfile and OSV.
✓That route is being hit right nowClickHouse · CLICKHOUSE CLOUD
184 requests on 3 candidate routes in the last 5 min, 138 unblocked · 10 journey, 126 patient, 48 marker
ClickHouse decision: /portal/messages · 80 requests in 5 min, 34 unblocked, hostile traffic on this route → exposed route → BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
The agent's query
SELECT route_id, client_kind, count() AS total, countIf(blocked = 0) AS unblocked
FROM bg.edge_requests
WHERE site = 'managed' AND route_id IN ('portal.book', 'portal.messages', 'portal.billpay')
  AND ts >= now() - INTERVAL 300 SECOND
GROUP BY route_id, client_kind
✓ BOTH FACTORS: MAY ACTStatic evidence alone, or traffic alone, never triggers a change.

fig. 3 Decision · one control ID from the catalog

guild:code~breakglass-decision · structured output
BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
Refuse server-action requests that carry no signed-in session
  • Semgrep confirms all three portal server-action routes are reachable via vulnerable React server functions.
  • ClickHouse shows live hostile traffic (marker clients) on /portal/messages, which is reachable and not required for core patient care.
  • The catalog's narrowest eligible control covering the exploited unauthenticated route is BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS, blocking unauthenticated server-action requests everywhere, per advisory.
  • Shut-down was denied by hospital policy, so this is the strongest reversible control with low blast radius.
Considered and not chosen (1)
  • BG-CTL-PORTAL-DISABLE-MESSAGES Lower-ranked controls do not block unauthenticated traffic across all reachable routes: only BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS fully mitigates per advisory.
reversibleblocking ruletouches no critical routepolicy: ALLOWconfidence 0.98

fig. 6 Controls applied

Every change, and every undo
ControlAppliedOutcome
BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS05:16:20 UTCcontained
Exposure 0 and the patient journey passed.

fig. 4 Verification · risk down, care up

ClickHouse, per 10 s
probes that got through to /portal/messages, per 10 s
2005:14:5005:16:40control applied0
patient journeys passing, % (one every 30 s; held between runs)
100005:14:5005:16:40control applied100%
Sign in✓ 99 ms
jordan.lee → /portal
Find a slot✓ 12 ms
8 slots listed
Book✓ 58 ms
Next-Action: book → 200
Confirm✓ 1 ms
Booked · MV-EQSE
✓ EXPOSURE 0 UNBLOCKED / 20s✓ PATIENT JOURNEY · PLAYWRIGHT✓ CRITICAL ROUTES 0 × 5xx
fig. 5Agent trace · hosted and run in Guild 01a10a7d-84ca-351a-0000-d89cf8839c33open in Guild ↗Guild's record →every tool call, logged
0100:00.1triggeradvisory.insert CVE-2025-55182 entered the advisory stream (REPLAY) → session started
0200:00.1toolinventory.match portal · react-server-dom-webpack 19.1.0 implements React Server Components
0300:00.9triggerguild.session Guild session 01a10a7d-84ca-351a-0000-d89cf8839c33 started for code~breakglass-decision
1500:04.2guildguild.llm model call · gpt-4.1 (openai)
1600:05.9guildguild.llm model asked for breakglass_incident_context, breakglass_inventory_match
1700:06.4guildguild.tool tool call (incident_id=INC-0012)
1800:06.6guildguild.tool tool call (incident_id=INC-0012)
0400:07.4toolosv.query react-server-dom-webpack@19.1.0: affected (GHSA-fv66-9v8q-g76r)
1900:08.0guildguild.llm model call · gpt-4.1 (openai)
2000:08.8guildguild.llm model asked for breakglass_clickhouse_route_traffic, breakglass_semgrep_reachability
2100:09.1guildguild.tool tool call (incident_id=INC-0012)
2200:09.2guildguild.tool tool call (incident_id=INC-0012)
0500:09.9toolclickhouse.route_traffic 184 requests on 3 candidate route(s) in 5 min · hostile on portal.messages
0600:11.0toolsemgrep.reachability reachable · 6 finding(s) · routes portal.book, portal.billpay, portal.messages
2300:11.6guildguild.llm model call · gpt-4.1 (openai)
2400:12.6guildguild.llm model asked for breakglass_catalog_controls
2500:12.9guildguild.tool tool call (incident_id=INC-0012)
0700:13.4toolcatalog.list 4 of 7 controls eligible for portal · ranker's first: BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
2600:14.0guildguild.llm model call · gpt-4.1 (openai)
2700:14.8guildguild.llm model asked for breakglass_services_shutdown
2800:15.1guildguild.tool tool call (asset_id=portal)
2900:15.3policyedge.shutdown(portal) DENIED by Guild's credential policy · services_shutdown (asked because the hospital's playbook says strongest containment first)
3000:15.3guildguild.policy DENIED {'error': 'Forbidden', 'message': "Access to 'services_shutdown' is not permitted for this integration. Ask a workspace admin to update credential policies."}
3100:15.7guildguild.llm model call · gpt-4.1 (openai)
3200:17.0guildguild.llm model asked for breakglass_human_approval
3300:17.2guildguild.tool tool call (incident_id=INC-0012, summary=Portal shutdown was denied by policy; hostile unauthenticate)
0800:17.7approvalbatonpass.handoff approval handoff h_01M457VHP3DG5EK9ESA0BZR7Z7 waiting for IT on-call (QR on the refusal card)
3400:18.3guildguild.llm model call · gpt-4.1 (openai)
3500:19.9guildguild.llm model asked for breakglass_submit_decision
3600:20.2guildguild.tool tool call (alternatives=[{'control_id': 'BG-CTL-PORTAL-DISABLE-MESSAGES', 'why_not':, confidence=0.98, control_id=BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS, incident_id=INC-0012, reasons=['Semgrep confirms all three portal server-action routes are)
0900:20.4policygate.check ALLOWED BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS: all checks passed
1000:20.5llmdecide guild:code~breakglass-decision → BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS (confidence 0.98, 0 turns)
1100:20.7tooledge.apply BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS → ALLOWED by credential policy (allow-apply-catalog)
3700:21.0guildguild.llm model call · gpt-4.1 (openai)
3800:22.6guildguild.reply BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
3900:22.8guildguild.done BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
1200:41.1verifyexposure 0 unblocked of 3 hostile requests in 20 s on portal.book, portal.messages
1300:41.1verifyjourney Sign in ✓ → Find a slot ✓ → Book ✓ → Confirm ✓ (PLAYWRIGHT, 0.2 s)
1400:41.4statecontained exposure clock stopped at 0:41 · Refuse server-action requests that carry no signed-in session · watch armed
4005:16.7approvalbatonpass.decision Test tap (headless phone browser, not a person): IT on-call decided on the phone: approve (BatonPass handoff h_01M457VHP3DG5EK9ESA0BZR7Z7, state solved)
4105:16.9approvalhuman.shutdown Test tap (headless phone browser, not a person): IT on-call approved by phone: Patient portal taken offline under human authority
Watch retiredAny unblocked non-patient request to /portal/messages reopens INC-0012W-0011

fig. 7 Attack timeline · ClickHouse

UTC · from the request log and this incident's events

Peak 2 hostile requests per 10 s to /portal/messages · 2 blocked after the control.

TimeWhat happenedSource
05:15:00 UTCFirst hostile request in the recorded window
1 non-patient request to /portal/messages in that 10 s (the window starts 60 s before the incident opened)
ClickHouse
05:15:59 UTCAdvisory ingested
CVE-2025-55182 entered the advisory stream (replay of a real KEV entry)
MongoDB
05:16:09 UTCEvidence query
184 requests on 3 candidate route(s) in 5 min · hostile on portal.messages
ClickHouse
05:16:15 UTCShutdown denied
BG-CTL-PORTAL-SHUTDOWN refused (Guild's own time)
Guild credential policy
05:16:20 UTCControl applied
BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
edge
05:16:30 UTCFirst 10 s with nothing getting through
2 hostile requests blocked, 0 through
ClickHouse
05:16:41 UTCVerified close
exposure 0 unblocked · patient journey passed · 0 × 5xx on critical routes
ClickHouse + Playwright

fig. 0 The advisory

What the government's list says
CVE-2025-55182Replay of a real KEV entryRansomware use: known
Meta React Server Components Remote Code Execution Vulnerability

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

Added to KEV
Dec 5, 2025
Federal due date
Dec 12, 2025 (7 days after listing)
EPSS
99.8% chance of exploitation in 30 days · top 0.5% (2026-10-04)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Timeline

UTC
Advisory ingested
05:15:59 UTC
Trigger
Replay of a real KEV entry into the advisory stream
Agent runtime
Hosted and run in Guild · Guild's record · strategy: containment-first
Opened
05:15:59 UTC
Closed
05:16:41 UTC

Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.