Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2025-55182: What you need to know about React2Shell

bugcrowd.com | vulnerability | Critical | Actively exploited | CVE-2025-55182 | #rce

Summary

On December 3, 2025, the React Team disclosed a critical remote code execution (RCE) vulnerability affecting React Server Components, commonly used in modern Next.js deployments. An unauthenticated attacker could craft a malicious HTTP request that, when deserialized by React, results in remote code execution on the server. Additional technical details will be released once the […]
CVSS
10
Published
Collected

original ↗

Related coverage

back