logo

Critical React2Shell flaw actively exploited in China-linked attacks

ID: b5cd4b2c-c35c-55d6-8d33-0c65ef0778c6

STIX ID: report--b5cd4b2c-c35c-55d6-8d33-0c65ef0778c6

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-12-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**React2Shell (CVE-2025-55182)** is an unauthenticated insecure-deserialization RSC 'Flight' protocol flaw in React/Next.js that allows remote JavaScript execution; public PoCs appeared quickly and AWS observed China-linked threat actors (Earth Lamia, Jackpot Panda) actively exploiting the issue within hours of disclosure, while tooling and scanners (and vendor patches) are available but many deployments remain vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.