Breakglass
Incidents
← IncidentsConnecting…
INC-0015·Mercy Valley Community Hospital·Patient portalReplay of a real KEV entrySimulated hospital

Meta React Server Components flaw on the patient portal: contained without taking patient routes offline

CVE-2025-55182, Meta React Server Components (CISA KEV). The fixed version can't be installed today. Breakglass proves the flaw matters here, applies one reversible control, and proves patients can still book.

✓ CONTAINED
1:26
exposure closed, from ingest to verified
federal due window: 7 days

fig. 1 Evidence · two factors before any action

Could it happen here? Is it happening?
✓The code reaches the flawed partSemgrep · SEMGREP CE
targets/mercy-portal/app/appointments/actions.ts:6 React Server Function `bookAppointment` is exported from a "use server" module. Requests to it are decoded by react-server-dom-*; CVE-2025-55182 (CISA KEV) is a flaw in that decoding for affected versions.
export async function bookAppointment(slotId: string) {
  const session = await requireSession();
  return schedule.book(session.patientId, slotId);
targets/mercy-portal/app/appointments/page.tsx:10 A route component invokes server function `bookAppointment`, so the endpoint that decodes its payload is reachable from that route.
{s.label} <button onClick={() => bookAppointment(s.id)}>Book</button>
4 more findings
targets/mercy-portal/app/billpay/actions.ts:6 React Server Function `payBalance` is exported from a "use server" module. Requests to it are decoded by react-server-dom-*; CVE-2025-55182 (CISA KEV) is a flaw in that decoding for affected versions.
targets/mercy-portal/app/billpay/page.tsx:4 A route component invokes server function `payBalance`, so the endpoint that decodes its payload is reachable from that route.
targets/mercy-portal/app/messages/actions.ts:10 React Server Function `sendCareTeamMessage` is exported from a "use server" module. Requests to it are decoded by react-server-dom-*; CVE-2025-55182 (CISA KEV) is a flaw in that decoding for affected versions.
targets/mercy-portal/app/messages/page.tsx:4 A route component invokes server function `sendCareTeamMessage`, so the endpoint that decodes its payload is reachable from that route.
rule bg-rsc-server-action-defined · direct dependency react-server-dom-webpack 19.1.0 · 1.2 s
Custom rules over the portal source: server functions defined and invoked from 3 route(s). Semgrep Community Edition (no account); the affected version comes from the lockfile and OSV.
✓That route is being hit right nowClickHouse · CLICKHOUSE CLOUD
54 requests on 3 candidate routes in the last 5 min, 54 unblocked · 4 journey, 32 patient, 18 marker
ClickHouse decision: /portal/messages · 23 requests in 5 min, 23 unblocked, hostile traffic on this route → exposed route → BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
One query, 9.5 ms in ClickHouse · read 8,207 rows (89 KB) · analytics →
The query that decided
SELECT route_id, client_kind,
count() AS n_total,
countIf(blocked = 0) AS n_unblocked,
countIf(blocked != 0) AS n_blocked,
min(ts) AS first_ts,
max(ts) AS last_ts
FROM bg.edge_requests
WHERE site = 'managed' AND ts >= '2026-10-09 19:56:59.985' AND has(['portal.book', 'portal.messages', 'portal.billpay'], route_id)
GROUP BY route_id, client_kind
ORDER BY route_id, client_kind
✓ BOTH FACTORS: MAY ACTStatic evidence alone, or traffic alone, never triggers a change.

fig. 3 Decision · one control ID from the catalog

guild:code~breakglass-decision · structured output
BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
Refuse server-action requests that carry no signed-in session
  • Semgrep confirms server-action vulnerability is reachable from all three portal routes: booking, billpay, and messages.
  • Live ClickHouse traffic shows active patient traffic on /portal/appointments/book and /portal/messages, both exposed; billpay is reachable but not recently hit.
  • CISA advisory explicitly says unauthenticated RCE; the 'require session for actions' control covers all exposed routes in scope, including hostile traffic on messages, while letting patient journeys continue.
  • Rejected alternatives: disabling messages or limiting message body do not cover all exposed routes; shutting portal down disables critical patient care.
Considered and not chosen (3)
  • BG-CTL-PORTAL-DISABLE-MESSAGES Does not cover other exposed/hostile routes (e.g., booking, billpay) while 'require session' does.
  • BG-CTL-PORTAL-BLOCK-ACTIONS-EXCEPT-BOOKING Leaves booking route exposed, and advisory warns of unauthenticated RCE; 'require session' covers all at once.
  • BG-CTL-PORTAL-BLOCK-ALL-ACTIONS Would disable critical routes (e.g., booking), impacting patient care, while 'require session' effectively contains unauthenticated attack.
reversibleblocking ruletouches no critical routepolicy: ALLOWconfidence 1.00

fig. 6 Controls applied

Every change, and every undo
ControlAppliedOutcome
BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS20:02:11 UTCcontained
Exposure 0 and the patient journey passed.

fig. 4 Verification · risk down, care up

ClickHouse, per 10 s
probes that got through to /portal/messages, per 10 s
2020:00:0020:02:30control applied0
patient journeys passing, % (one every 30 s; held between runs)
100020:00:0020:02:30control applied100%
Sign in✓ 120 ms
jordan.lee → /portal
Find a slot✓ 14 ms
8 slots listed
Book✓ 61 ms
Next-Action: book → 200
Confirm✓ 1 ms
Booked · MV-BSET
✓ EXPOSURE 0 UNBLOCKED / 20s✓ PATIENT JOURNEY · PLAYWRIGHT✓ CRITICAL ROUTES 0 × 5xx
Proved by 2 ClickHouse queries: 24.1 ms in ClickHouse · read 24,607 rows
fig. 5Agent trace · hosted and run in Guild 01a12241-45fc-351a-0000-1135afe8fa4dopen in Guild ↗Guild's record →every tool call, logged
0100:00.0triggeradvisory.insert CVE-2025-55182 entered the advisory stream (REPLAY) → session started
0200:00.1toolinventory.match portal · react-server-dom-webpack 19.1.0 implements React Server Components
0300:00.6triggerguild.session Guild session 01a12241-45fc-351a-0000-1135afe8fa4d started for code~breakglass-decision
0400:48.1toolosv.query react-server-dom-webpack@19.1.0: affected (GHSA-fv66-9v8q-g76r)
0500:55.1toolclickhouse.route_traffic 54 requests on 3 candidate route(s) in 5 min · hostile on portal.messages · CLICKHOUSE CLOUD read 8,207 rows in 9.5 ms (server)
0600:56.5toolsemgrep.reachability reachable · 6 finding(s) · routes portal.book, portal.billpay, portal.messages
0701:00.1toolcatalog.list 1 of 7 controls eligible for portal · ranker's first: BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
0801:05.9policygate.check ALLOWED BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS: all checks passed
0901:06.0llmdecide guild:code~breakglass-decision → BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS (confidence 1.00, 0 turns)
1001:06.2tooledge.apply BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS → ALLOWED by credential policy (allow-apply-catalog)
1101:26.5verifyexposure 0 unblocked of 3 hostile requests in 20 s on portal.book, portal.messages · CLICKHOUSE CLOUD read 24,607 rows in 24.1 ms (server)
1201:26.6verifyjourney Sign in ✓ → Find a slot ✓ → Book ✓ → Confirm ✓ (PLAYWRIGHT, 0.2 s)
1301:26.8statecontained exposure clock stopped at 1:26 · Refuse server-action requests that carry no signed-in session · watch armed
Watch armedAny unblocked non-patient request to /portal/messages reopens INC-0015W-0014

fig. 7 Attack timeline · ClickHouse

UTC · from the request log and this incident's events

Peak 2 hostile requests per 10 s to /portal/messages · 2 blocked after the control.

TimeWhat happenedSource
20:00:10 UTCFirst hostile request in the recorded window
1 non-patient request to /portal/messages in that 10 s (the window starts 60 s before the incident opened)
ClickHouse
20:01:04 UTCAdvisory ingested
CVE-2025-55182 entered the advisory stream (replay of a real KEV entry)
MongoDB
20:02:00 UTCEvidence query
54 requests on 3 candidate route(s) in 5 min · hostile on portal.messages · CLICKHOUSE CLOUD read 8,207 rows in 9.5 ms (server) · read 8,207 rows in 9.5 ms in ClickHouse
ClickHouse
20:02:11 UTCControl applied
BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
edge
20:02:20 UTCFirst 10 s with nothing getting through
1 hostile request blocked, 0 through
ClickHouse
20:02:31 UTCVerified close
exposure 0 unblocked · patient journey passed · 0 × 5xx on critical routes
ClickHouse + Playwright

fig. 0 The advisory

What the government's list says
CVE-2025-55182Replay of a real KEV entryRansomware use: known
Meta React Server Components Remote Code Execution Vulnerability

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.

Added to KEV
Dec 5, 2025
Federal due date
Dec 12, 2025 (7 days after listing)
EPSS
99.8% chance of exploitation in 30 days · top 0.5% (2026-10-09)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Timeline

UTC
Advisory ingested
20:01:04 UTC
Trigger
Replay of a real KEV entry into the advisory stream
Agent runtime
Hosted and run in Guild · Guild's record · strategy: containment-first
Opened
20:01:05 UTC
Closed
20:02:31 UTC

Mercy Valley is a fictional hospital; its portal is a harmless twin and the "attack" traffic is a benign marker request. What's live and what's simulated.