top of page
perceptive_background_267k.jpg

React2Shell: Decoding CVE-2025-55182 – The Silent Threat in React Server Components

Published:

11 december 2025 om 07:41:39

Alert date:

11 december 2025 om 08:01:04

Source:

blog.qualys.com

Click to open the original link from this advisory

A critical remote code execution vulnerability dubbed 'React2Shell' was disclosed on December 3, 2025, affecting React Server Components and frameworks like Next.js. The vulnerability, CVE-2025-55182, has a CVSS score of 10.0 and could lead to full server takeover. It is currently under active exploitation and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Organizations using React Server Components and Next.js frameworks should take immediate remediation steps. The flaw represents a silent threat that can compromise entire server infrastructures through React-based applications.

Technical details

Mitigation steps:

Affected products:

React Server Components
Next.js

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page