logo

React2Shell: Serious RCE Vulnerability Threatening the Latest Web Frameworks (CVE-2025-55182)

ID: 7347a850-beb2-5658-89eb-d455d008cb1f

STIX ID: report--7347a850-beb2-5658-89eb-d455d008cb1f

Feed Name: ASEC

Threat Score
90/100

Date Published: 2025-12-18

Date Updated: 2026-04-26

Author: ATCP

...
...

In December 2025 AhnLab published a technical analysis of CVE-2025-55182 (“React2Shell”), a critical (CVSS 10.0) vulnerability in React Server Components' Flight protocol that permits unauthenticated arbitrary code execution by combining fake chunk injection, prototype pollution via property-path traversal, and a Function constructor gadget; the report explains the attack flow, shows exploitation details, and recommends immediate package updates, payload blocking, and temporary mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.