React.js Hit by Maximum-Severity 'React2Shell' Vulnerability
ID: 0b658b0a-d21f-5385-be01-158d97991045
STIX ID: report--0b658b0a-d21f-5385-be01-158d97991045
Feed Name: Infosecurity Magazine (News)
React2Shell: a critical, unauthenticated remote code execution vulnerability affecting server-side React.js (CVE-2025-55182) and a related Next.js advisory (CVE-2025-66478). The flaw has a CVSS score of 10.0, is trivially exploitable via a single HTTP request in default configurations (including React Server Function endpoints and default Next.js setups), has published PoCs and reports of active exploitation, and remediation is to upgrade to fixed React/Next.js package versions immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
