Skip to content
P
非影
top
latest
vulnerabilities
research
tools
Topics
sources
search
search
🌓
中文
Curated security research, vulnerabilities, advisories and tools for practitioners.
$170k in Bypasses: The Vercel React2Shell Challenge
hacktron.ai
| blog |
#bug-bounty
|
#react2shell
|
#nextjs
|
#challenge
|
#waf-bypass
|
#vercel
Summary
Hacktron teamed with Vercel on the React2Shell challenge, awarding $170k in bounties for WAF bypasses submitted against Vercel's protections.
Published
2026-05-04 00:00
Collected
2026-09-20 03:19
original ↗
← Previous
Hacktron Review for Open Source
Next →
Why Mythos doesn't matter (for us)
Related coverage
blog
·
portswigger.net
How to detect React2Shell with Burp Suite
Burp Suite's default scans now detect React2Shell (CVE-2025-55182 and CVE-2025-66478), two critical unauthenticated RCE flaws in React server components affecting Next.js applications.
Critical
·
vulnerability
·
xbow.com
React2Shell (CVE-2025-55182): A Wake-Up Call for Modern Web Security and How XBOW Helps You Respond
Covers React2Shell (CVE-2025-55182), an unauthenticated RCE in React Server Components' serialization that also affects Next.js and more, and how to quickly scope exposure.
High
·
vulnerability
·
aikido.dev
React & Next.js DoS Vulnerability (CVE-2025-55184): What You Need to Fix After React2Shell
CVE-2025-55184 is a DoS flaw in React Server Components tied to the same Flight deserialization layer as React2Shell; crafted requests hang servers, and teams must also patch follow-up CVE-2025-67779.
Critical
·
advisory
·
github.com
[CVE-2026-94545] Remote Code Execution in next/og ImageResponse
Dynamic Open Graph image generation is common in Next.js apps; any route accepting user parameters to customize SVG cards could lead to full Node.js server compromise.
vulnerability
·
jfrog.com
CVE-2025-55182 and CVE-2025-66478 (“React2Shell”): All you need to know – UPDATED
JFrog's living advisory on React2Shell (CVE-2025-55182 / CVE-2025-66478): a near-100%-success RCE in React Server Functions and Next.js, now with public exploits, plus follow-on DoS fixes.
blog
·
hacktron.ai
vinext: Vibe-Hacking Cloudflare's Vibe-Coded Next.js Replacement
Cloudflare built a Next.js replacement in a week with AI for $1100. We pointed Hacktron at it to find what the tests missed.
back