logo

React2Shell Exploits Flood the Internet as Attacks Continue

ID: fcd6b83e-6584-5b75-b11c-1e5c72131804

STIX ID: report--fcd6b83e-6584-5b75-b11c-1e5c72131804

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-12-12

Date Updated: 2026-04-21

Author: Rob Wright

...
...

A critical RCE vulnerability identified as CVE-2025-55182 (nicknamed "React2Shell") in React Server Components has triggered a flood of public PoC exploits—many ineffective or AI-generated, but some validated and dangerous (including ones that deploy the Godzilla web shell). Researchers report active exploitation in the wild by various actors (including China-nexus groups), use of cryptominers, infostealers and backdoors, and growing efforts to bypass or evade WAF protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.