logo

Detecting React2Shell: The maximum-severity RCE vulnerability affecting React Server Components and Next.js

ID: 55828d27-d64f-527c-948f-31ff28714256

STIX ID: report--55828d27-d64f-527c-948f-31ff28714256

Feed Name: Sysdig Blog

Threat Score
95/100

Date Published: 2025-12-05

Date Updated: 2026-05-01

...
...

On December 3, 2025, a critical unauthenticated RCE vulnerability dubbed "React2Shell" (CVE-2025-55182) was disclosed in React Server Components' Flight protocol, affecting multiple react-server-dom packages and numerous frameworks (including Next.js tracked as CVE-2025-66478); public PoCs and reports of near-100% exploitation against default configurations make this a high-risk, mass-exploitation threat, and the report provides technical analysis, Falco detection rules, WAF mitigations, scanners, and required patch versions as remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.