


Perceptive Security
SOC/SIEM Consultancy

React2Shell critical flaw actively exploited in China-linked attacks
Published:
5 december 2025 om 11:26:07
Alert date:
5 december 2025 om 12:01:17
Source:
bleepingcomputer.com

Multiple China-linked threat actors are actively exploiting the React2Shell vulnerability (CVE-2025-55182) affecting React and Next.js applications. The max-severity flaw began being exploited just hours after its public disclosure. The vulnerability represents a critical security issue in widely-used JavaScript frameworks. Chinese threat groups quickly weaponized the vulnerability for attacks. The rapid exploitation timeline highlights the risk of zero-day disclosure without adequate patching time.
Technical details
Mitigation steps:
Affected products:
React
Next.js
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.