logo

React2Shell (CVE-2025-55182) Deserialization to Remote Code Execution in React and Next.js

ID: 348a94cc-5eb6-57c5-9917-4aeaeaa18b97

STIX ID: report--348a94cc-5eb6-57c5-9917-4aeaeaa18b97

Feed Name: Checkmarx Zero

Threat Score
95/100

Date Published: 2025-12-04

Date Updated: 2026-04-27

Author: Alex Shleymovich

...
...

Checkmarx reports a critical unauthenticated remote code execution vulnerability (React2Shell, CVE-2025-55182) in React Server Components and related packages that stems from unsafe deserialization of Server Function requests; the advisory describes the root cause, exploitation paths (including invoking dangerous bundled Node modules), affected packages (React, Next.js, react-server-dom-* and others), and provides fixed versions and upgrade guidance to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.