A log-level reconstruction of CVE-2025-55182 (React2Shell) on a live Next.js app: RCE via the RSC Flight protocol, 12,440 logs, four C2 servers—though a stripped container blocked later stages.
Wiz details CVE-2025-55182 exploit mechanics—insecure deserialization in React Server Components—and maps in-the-wild attacks from cryptomining and credential harvesting to Sliver backdoors.
A critical CVE-2025-55182 React RCE flaw affects millions of sites. Get impact details, affected versions, indicators of compromise, and urgent remediation steps.
Covers React2Shell (CVE-2025-55182), an unauthenticated RCE in React Server Components' serialization that also affects Next.js and more, and how to quickly scope exposure.
The React team disclosed CVE-2025-55182, an unauthenticated RCE in React Server Components used by Next.js. Bugcrowd has activated priority triage for related submissions.
React2Shell (CVE-2025-55182) is a critical unauthenticated RCE in React Server Components, exploitable in default Next.js deployments. Wiz confirms active exploitation and urges immediate patching.