logo

CVE-2025-55182: Critical Vulnerability, React2Shell, Allows for Unauthenticated RCE

ID: 7ea3147c-44c3-5b59-bd52-c57782781b2e

STIX ID: report--7ea3147c-44c3-5b59-bd52-c57782781b2e

Feed Name: Cybereason Blog

Threat Score
95/100

Date Published: 2025-12-05

Date Updated: 2026-04-27

Author: Cybereason Consulting Team

...
...

Cybereason warns of a critical unauthenticated remote code execution vulnerability in React Server Components (CVE-2025-55182, “React2Shell”) affecting React 19.0.0–19.2.0 and frameworks that bundle RSC (e.g., Next.js); public PoCs are available and exploitation has been observed shortly after disclosure, with attribution to China-linked groups — organizations should apply the provided patches, monitor for malformed RSC requests and unexpected process execution, and investigate internet-exposed servers for compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.