logo

Cato CTRL™ Threat Brief: “React2Shell” Vulnerability Targeting React Server Components

ID: 373139d7-bb74-57a4-b256-6f8d9cd189ae

STIX ID: report--373139d7-bb74-57a4-b256-6f8d9cd189ae

Feed Name: Cato Networks

Threat Score
85/100

Date Published: 2025-12-09

Date Updated: 2026-07-23

Author: Dr. Guy Waizel

...
...

**Executive Summary:** A critical remote code execution vulnerability named React2Shell (CVE-2025-55182) in React Server Components was disclosed and followed by public PoCs, triggering mass scanning and more than 10,000 exploitation attempts targeting multiple sectors and frameworks (react-server-dom-* packages, Next.js, Vite, Parcel plugins, Redwood SDK, etc.); Cato CTRL observed diverse payloads, exploitation patterns including prototype pollution, and activity attributed to state-nexus groups, and deployed IPS protections across its SASE platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.