React2Shell (CVE-2025-55182): Node.js RCE Against a Production Next.js App
hunt.io | vulnerability | Critical | Actively exploited | CVE-2025-55182 | #rce | #vulnerability | #nextjs | #cve-2025-55182 | #react | #nodejs
Summary
A log-level reconstruction of CVE-2025-55182 (React2Shell) on a live Next.js app: RCE via the RSC Flight protocol, 12,440 logs, four C2 servers—though a stripped container blocked later stages.
- CVE
- CVE-2025-55182
- CVSS
- 10
- Published
- Collected
Skip to content