


Perceptive Security
SOC/SIEM Consultancy

React2Shell: Decoding CVE-2025-55182 – The Silent Threat in React Server Components
Published:
11 december 2025 om 07:41:39
Alert date:
11 december 2025 om 08:01:04
Source:
blog.qualys.com
A critical remote code execution vulnerability dubbed 'React2Shell' was disclosed on December 3, 2025, affecting React Server Components and frameworks like Next.js. The vulnerability, CVE-2025-55182, has a CVSS score of 10.0 and could lead to full server takeover. It is currently under active exploitation and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Organizations using React Server Components and Next.js frameworks should take immediate remediation steps. The flaw represents a silent threat that can compromise entire server infrastructures through React-based applications.
Technical details
Mitigation steps:
Affected products:
React Server Components
Next.js
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
