logo

Next.js Released a Scanner to Detect and Update Apps Impacted by React2Shell Vulnerability

ID: 15131701-bf05-5c44-b551-6203a152827e

STIX ID: report--15131701-bf05-5c44-b551-6203a152827e

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Abinaya

...
...

A new CLI tool, fix-react2shell-next, is available to detect and automatically patch the critical React2Shell RCE (CVE-2025-66478) in Next.js and React Server Components by recursively scanning package.json files (including monorepos), upgrading identified vulnerable packages to specified patched versions, and refreshing lockfiles; the advisory lists affected version ranges and provides npx usage with dry-run, json, and forced-fix options.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.