Cato CTRL™ Threat Brief: “React2Shell” Vulnerability Targeting React Server Components
ID: 373139d7-bb74-57a4-b256-6f8d9cd189ae
STIX ID: report--373139d7-bb74-57a4-b256-6f8d9cd189ae
Feed Name: Cato Networks
**Executive Summary:** A critical remote code execution vulnerability named React2Shell (CVE-2025-55182) in React Server Components was disclosed and followed by public PoCs, triggering mass scanning and more than 10,000 exploitation attempts targeting multiple sectors and frameworks (react-server-dom-* packages, Next.js, Vite, Parcel plugins, Redwood SDK, etc.); Cato CTRL observed diverse payloads, exploitation patterns including prototype pollution, and activity attributed to state-nexus groups, and deployed IPS protections across its SASE platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
