React2Shell Vulnerability Under Attack From China-Nexus Groups
ID: 75ada5a9-414f-5812-85a6-68adc2542c3a
STIX ID: report--75ada5a9-414f-5812-85a6-68adc2542c3a
Feed Name: Dark Reading
Threat Score
A critical unauthenticated RCE in React Server Components (CVE-2025-55182, dubbed "React2Shell") — with a CVSS score of 10 and downstream impact on Next.js (CVE-2025-66478) — is being actively targeted. Amazon observed exploitation attempts by China-nexus groups (Earth Lamia, Jackpot Panda) using automated scans and public PoCs; vendors and maintainers have released patches and mitigations and organizations are urged to apply them immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
