logo

CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js

ID: 35aac35b-451a-54bf-a93d-bb1d13aae49a

STIX ID: report--35aac35b-451a-54bf-a93d-bb1d13aae49a

Feed Name: Datadog Security Labs

Threat Score
85/100

Date Published: 2025-12-04

Date Updated: 2026-04-27

...
...

A critical server-side prototype pollution vulnerability in React Server Components (CVE-2025-55182) — which also affects Next.js installations — allows unauthenticated remote code execution; public PoCs and a working exploit were published that can compromise even blank create-next-app instances. Datadog observed scanning activity from over 80 IPs probing for this flaw soon after disclosure; patches were committed and upgrading affected React/Next.js components is the recommended remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.