CVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild Exploitation
ID: 3682a370-e399-5fc3-8060-d984060cd056
STIX ID: report--3682a370-e399-5fc3-8060-d984060cd056
Feed Name: TrendAI Security Blog
Threat Score
This report analyzes CVE-2025-55182 (React2Shell), a critical pre-authentication RCE in React Server Components' Flight deserialization that enables attackers to reach the Function constructor and execute arbitrary Node.js commands; it documents exploitation chains, observed campaigns delivering Mirai, Cobalt Strike, Sliver, and other payloads, provides IoCs, mitigation guidance, and patched versions for React/Next.js.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
