logo

Inside Vercel’s sleep-deprived race to contain React2Shell

ID: 94ba7734-9839-5d36-9a16-7a2b4d72acb2

STIX ID: report--94ba7734-9839-5d36-9a16-7a2b4d72acb2

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2026-01-08

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

The report details React2Shell (CVE-2025-55182), a critical unauthenticated RCE affecting React Server Components and downstream frameworks like Next.js; it prompted an industry-wide emergency response, platform mitigations, and a patch from the React team. The defect saw rapid, widespread exploitation — including millions of attack attempts, dozens of impacted organizations, and a surge in public exploits — and led Vercel to run a coordinated bounty program and mitigation efforts to block exploit attempts and share findings with cloud providers and the open-source community.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.