logo

Understanding React2Shell: Critical Remote Code Execution in React Server Components and Next.js

ID: d88005c8-9d20-5ae2-b0e0-3384d1b4b6d2

STIX ID: report--d88005c8-9d20-5ae2-b0e0-3384d1b4b6d2

Feed Name: Outpost24 Blog

Threat Score
85/100

Date Published: 2025-12-15

Date Updated: 2026-04-28

Author: dimber

...
...

React2Shell is a critical deserialization vulnerability (CVE-2025-55182) in React Server Components and Next.js that enables unauthenticated remote code execution via the Flight protocol; active exploitation has been observed with attackers deploying cryptocurrency miners, backdoors, and persistence tooling. The advisory details affected packages and versions, recommended patching of both React and framework dependencies, inventory and runtime monitoring steps, and broader risk-management guidance to reduce reintroduction of vulnerable RSC components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.