logo

React2Shell: Decoding CVE-2025-55182 – The Silent Threat in React Server Components

ID: a7771501-3f67-5b06-8568-017e9f5d30a7

STIX ID: report--a7771501-3f67-5b06-8568-017e9f5d30a7

Feed Name: Qualys Blog

Threat Score
95/100

Date Published: 2025-12-11

Date Updated: 2026-04-28

Author: Kaustubh Jagtap

...
...

Executive summary: A critical RCE vulnerability called “React2Shell” (CVE-2025-55182, CVSS 10.0) in React Server Components was disclosed and is being actively exploited in the wild against internet-facing Next.js and other RSC-enabled applications; exploitation can yield full server takeover and has already been used to deploy cryptominers, backdoors (e.g., Sliver), and establish persistent shells. The advisory lists affected packages/versions, available patched releases, observed attacker behaviors (discovery, DNS/HTTP beaconing, reverse shells), and provides Qualys detection/QID coverage and mitigation/patching guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.