logo

Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat Actors

ID: 69518b5e-5896-5ce3-94a0-e55898fd2184

STIX ID: report--69518b5e-5896-5ce3-94a0-e55898fd2184

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2025-12-08

Date Updated: 2026-04-28

...
...

Recorded Future describes CVE-2025-55182 (React2Shell), a critical remote-code-execution vulnerability in React Server Components and related frameworks that has publicly available PoCs and is reported to be actively exploited (AWS and Datadog reporting scans and exploitation attempts); the report lists affected versions, mitigation patches, recommended scanning tools, and IP indicators linked to suspected Chinese threat actors while urging immediate patching and network defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.