CVE-2025-55182: Frequently Asked Questions About React2Shell: React Server Components Remote Code Execution Vulnerability
ID: 7e45942d-3592-55ea-baaa-cc207dd26b03
STIX ID: report--7e45942d-3592-55ea-baaa-cc207dd26b03
Feed Name: Tenable Blog
Threat Score
Tenable Research Special Operations details React2Shell (CVE-2025-55182), a CVSS 10 unauthenticated RCE in React Server Components affecting multiple react-server-dom packages and frameworks (including Next.js); public PoCs and reports of in-the-wild exploitation by China-linked actors have been observed, and fixed package versions and mitigations are provided—patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
