logo

React.js Hit by Maximum-Severity 'React2Shell' Vulnerability

ID: 0b658b0a-d21f-5385-be01-158d97991045

STIX ID: report--0b658b0a-d21f-5385-be01-158d97991045

Feed Name: Infosecurity Magazine (News)

Threat Score
95/100

Date Published: 2025-12-05

Date Updated: 2026-04-22

...
...

React2Shell: a critical, unauthenticated remote code execution vulnerability affecting server-side React.js (CVE-2025-55182) and a related Next.js advisory (CVE-2025-66478). The flaw has a CVSS score of 10.0, is trivially exploitable via a single HTTP request in default configurations (including React Server Function endpoints and default Next.js setups), has published PoCs and reports of active exploitation, and remediation is to upgrade to fixed React/Next.js package versions immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.