Meta React Server Components flaw on the patient portal: contained without taking patient routes offline
CVE-2025-55182, Meta React Server Components (CISA KEV). The fixed version can't be installed today. Breakglass proves the flaw matters here, applies one reversible control, and proves patients can still book.
fig. 1 Evidence · two factors before any action
Could it happen here? Is it happening?fig. 3 Decision · one control ID from the catalog
guild:code~breakglass-decision · structured output- Semgrep confirms server-action vulnerability is reachable from all three portal routes: booking, billpay, and messages.
- Live ClickHouse traffic shows active patient traffic on /portal/appointments/book and /portal/messages, both exposed; billpay is reachable but not recently hit.
- CISA advisory explicitly says unauthenticated RCE; the 'require session for actions' control covers all exposed routes in scope, including hostile traffic on messages, while letting patient journeys continue.
- Rejected alternatives: disabling messages or limiting message body do not cover all exposed routes; shutting portal down disables critical patient care.
Considered and not chosen (3)
BG-CTL-PORTAL-DISABLE-MESSAGESDoes not cover other exposed/hostile routes (e.g., booking, billpay) while 'require session' does.BG-CTL-PORTAL-BLOCK-ACTIONS-EXCEPT-BOOKINGLeaves booking route exposed, and advisory warns of unauthenticated RCE; 'require session' covers all at once.BG-CTL-PORTAL-BLOCK-ALL-ACTIONSWould disable critical routes (e.g., booking), impacting patient care, while 'require session' effectively contains unauthenticated attack.
fig. 6 Controls applied
Every change, and every undo| Control | Applied | Outcome |
|---|---|---|
| BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS | 20:02:11 UTC | contained Exposure 0 and the patient journey passed. |
fig. 4 Verification · risk down, care up
ClickHouse, per 10 sfig. 7 Attack timeline · ClickHouse
UTC · from the request log and this incident's eventsPeak 2 hostile requests per 10 s to /portal/messages · 2 blocked after the control.
| Time | What happened | Source |
|---|---|---|
| 20:00:10 UTC | First hostile request in the recorded window 1 non-patient request to /portal/messages in that 10 s (the window starts 60 s before the incident opened) | ClickHouse |
| 20:01:04 UTC | Advisory ingested CVE-2025-55182 entered the advisory stream (replay of a real KEV entry) | MongoDB |
| 20:02:00 UTC | Evidence query 54 requests on 3 candidate route(s) in 5 min · hostile on portal.messages · CLICKHOUSE CLOUD read 8,207 rows in 9.5 ms (server) · read 8,207 rows in 9.5 ms in ClickHouse | ClickHouse |
| 20:02:11 UTC | Control applied BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS | edge |
| 20:02:20 UTC | First 10 s with nothing getting through 1 hostile request blocked, 0 through | ClickHouse |
| 20:02:31 UTC | Verified close exposure 0 unblocked · patient journey passed · 0 × 5xx on critical routes | ClickHouse + Playwright |
fig. 0 The advisory
What the government's list saysMeta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.
- Added to KEV
- Dec 5, 2025
- Federal due date
- Dec 12, 2025 (7 days after listing)
- EPSS
- 99.8% chance of exploitation in 30 days · top 0.5% (2026-10-09)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Timeline
UTC- Advisory ingested
- 20:01:04 UTC
- Trigger
- Replay of a real KEV entry into the advisory stream
- Agent runtime
- Hosted and run in Guild · Guild's record · strategy: containment-first
- Opened
- 20:01:05 UTC
- Closed
- 20:02:31 UTC
Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.