CVE-2025-55182: Critical Vulnerability, React2Shell, Allows for Unauthenticated RCE
ID: 7ea3147c-44c3-5b59-bd52-c57782781b2e
STIX ID: report--7ea3147c-44c3-5b59-bd52-c57782781b2e
Feed Name: Cybereason Blog
Cybereason warns of a critical unauthenticated remote code execution vulnerability in React Server Components (CVE-2025-55182, “React2Shell”) affecting React 19.0.0–19.2.0 and frameworks that bundle RSC (e.g., Next.js); public PoCs are available and exploitation has been observed shortly after disclosure, with attribution to China-linked groups — organizations should apply the provided patches, monitor for malformed RSC requests and unexpected process execution, and investigate internet-exposed servers for compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
