logo

PoC Exploit Released for Critical React, Next.js RCE Vulnerability (CVE-2025-55182)

ID: c7a24ed9-6677-5759-8a87-2c9f58a83ce5

STIX ID: report--c7a24ed9-6677-5759-8a87-2c9f58a83ce5

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-05

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**React2Shell (CVE-2025-55182)**: A critical RCE in React Server Components and affected Next.js versions (CVSS 10.0) has a public PoC that executes arbitrary Node.js code via the Flight protocol; researchers and vendors released patches while scans report substantial exposure and early exploitation attempts by China-nexus groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.