CVE-2025-55182: What you need to know about React2Shell
Summary
On December 3, 2025, the React Team disclosed a critical remote code execution (RCE) vulnerability affecting React Server Components, commonly used in modern Next.js deployments. An unauthenticated attacker could craft a malicious HTTP request that, when deserialized by React, results in remote code execution on the server. Additional technical details will be released once the […]
- CVSS
- 10
- Published
- Collected
Skip to content