logo

Detecting React2Shell: The maximum-severity RCE vulnerability affecting React Server Components and Next.js

ID: 8b0146c3-9ed3-57b1-8035-3529fe739e0e

STIX ID: report--8b0146c3-9ed3-57b1-8035-3529fe739e0e

Feed Name: Sysdig Blog

Threat Score
90/100

Date Published: 2025-12-05

Date Updated: 2026-05-01

...
...

React2Shell (CVE-2025-55182) is a critical unauthenticated RCE in React Server Components (and tracked downstream in Next.js as CVE-2025-66478) that allows arbitrary server-side code execution via crafted HTTP payloads; a public PoC exists and researchers report near-100% exploitation against default configurations. The report documents affected packages and frameworks, provides technical analysis, offers runtime detection (Falco rule), WAF protections, and remediation guidance—recommending immediate patching to fixed versions and deployment of runtime detections where patching is not yet possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.