From React to Remote Code – Protecting Against the Critical React2Shell RCE Exposure
ID: 73de97a1-bf20-56f8-9f69-598ba2939b0c
STIX ID: report--73de97a1-bf20-56f8-9f69-598ba2939b0c
Feed Name: SentinelOne Blog
Threat Score
A critical unauthenticated remote code execution vulnerability dubbed React2Shell (CVE-2025-55182) in React Server Components and Next.js allows attackers to execute arbitrary code via unsafe deserialization of RSC Flight payloads; exploitation is highly reliable (near 100%), affects default deployments, and has been observed being weaponized by China-nexus threat groups, while vendors have released patches and SentinelOne offers detection and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
