logo

React2Shell: Technical Deep-Dive & In-the-Wild Exploitation of CVE-2025-55182

ID: efe2bb31-94e5-5e27-a613-8da93a46037a

STIX ID: report--efe2bb31-94e5-5e27-a613-8da93a46037a

Feed Name: Wiz Blog

Threat Score
78/100

Date Published: 2025-12-08

Date Updated: 2026-05-01

...
...

**Executive Summary:** The report documents CVE-2025-55182 (React2Shell), a critical RCE in React Server Components that is being actively exploited against Next.js and other RSC-enabled platforms; observed attacker activity includes credential harvesting, cloud metadata access, containerized cryptomining, Sliver-based persistent backdoors, fileless Node.js webshells and in-memory exfiltration, and the report provides PoC analysis, TTP descriptions and a long list of IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.