logo

Critical React, Next.js flaw lets hackers execute code on servers

ID: 9b15c09a-1da2-5793-a228-0c5464f27ed2

STIX ID: report--9b15c09a-1da2-5793-a228-0c5464f27ed2

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-12-04

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

### Executive summary A severe (CVSS 10/10) unauthenticated remote code execution vulnerability called "React2Shell" was disclosed in React Server Components (Flight) and inherited by Next.js via the react-server package; default configurations of react-server-dom-{parcel,turbopack,webpack} and many Next.js releases are impacted. The advisory lists affected versions and patched releases, warns the flaw stems from insecure deserialization, notes PoCs (some fake) and researcher guidance, and urges immediate auditing and applying the provided fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.