Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

React2Shell (CVE-2025-55182): Node.js RCE Against a Production Next.js App

hunt.io | vulnerability | Critical | Actively exploited | CVE-2025-55182 | #rce | #vulnerability | #nextjs | #cve-2025-55182 | #react | #nodejs

Summary

A log-level reconstruction of CVE-2025-55182 (React2Shell) on a live Next.js app: RCE via the RSC Flight protocol, 12,440 logs, four C2 servers—though a stripped container blocked later stages.
CVE
CVE-2025-55182
CVSS
10
Published
Collected

original ↗