logo

Critical CVE in React Server Components Actively Exploited

ID: 2c6764e9-4d9b-574f-937e-d9bd8b49d456

STIX ID: report--2c6764e9-4d9b-574f-937e-d9bd8b49d456

Feed Name: Aqua Security Blog

Threat Score
95/100

Date Published: 2025-12-09

Date Updated: 2026-04-26

...
...

A severe unauthenticated remote code execution vulnerability (CVE-2025-55182, "React2Shell") in React Server Components affects React 19.x and many Next.js integrations, enabling full server takeover via insecure deserialization. Rated CVSS 10.0 and rapidly weaponized, the flaw is being actively exploited by China-nexus actors, mass-scanning botnets, and opportunistic attackers; observed post-exploitation activity includes remote shells, cryptominers, credential harvesting, and persistence. Aqua recommends scanning, upgrading to patched versions, and applying runtime protections and CI/CD hardening to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.