React2Shell: Decoding CVE-2025-55182 – The Silent Threat in React Server Components
ID: a7771501-3f67-5b06-8568-017e9f5d30a7
STIX ID: report--a7771501-3f67-5b06-8568-017e9f5d30a7
Feed Name: Qualys Blog
Executive summary: A critical RCE vulnerability called “React2Shell” (CVE-2025-55182, CVSS 10.0) in React Server Components was disclosed and is being actively exploited in the wild against internet-facing Next.js and other RSC-enabled applications; exploitation can yield full server takeover and has already been used to deploy cryptominers, backdoors (e.g., Sliver), and establish persistent shells. The advisory lists affected packages/versions, available patched releases, observed attacker behaviors (discovery, DNS/HTTP beaconing, reverse shells), and provides Qualys detection/QID coverage and mitigation/patching guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
