CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

React2Shell: Remote Code Execution Vulnerability (CVE-2025-55182)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6273

As cited

Copy frozen at (site build).

vulnerabilities

React2Shell: Remote Code Execution Vulnerability (CVE-2025-55182)

CVE-2025-55182, a critical vulnerability in React Server Components with a CVSS score of 10.0, allows unauthenticated remote code execution through a flaw in the Flight protocol's deserialization process. Dubbed React2Shell, the vulnerability exploits prototype chain traversal and triggered over 4,100 exploitation attempts within hours of public disclosure on December 3, 2025, including attacks from a China-based threat actor. An update on December 15, 2025 revealed that initial patches were incomplete and identified two additional vulnerabilities (CVE-2025-55184 and CVE-2025-55183) requiring remediation in React 19 and affected Next.js versions.

Why it matters: Developers and operations teams running React Server Components or Next.js 15.x and 16.x must immediately patch to the corrected versions to prevent unauthenticated remote code execution, as active exploitation is confirmed.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

React2Shell: Remote Code Execution Vulnerability (CVE-2025-55182)

CVE-2025-55182, a critical vulnerability in React Server Components with a CVSS score of 10.0, allows unauthenticated remote code execution through a flaw in the Flight protocol's deserialization process. Dubbed React2Shell, the vulnerability exploits prototype chain traversal and triggered over 4,100 exploitation attempts within hours of public disclosure on December 3, 2025, including attacks from a China-based threat actor. An update on December 15, 2025 revealed that initial patches were incomplete and identified two additional vulnerabilities (CVE-2025-55184 and CVE-2025-55183) requiring remediation in React 19 and affected Next.js versions.

Why it matters: Developers and operations teams running React Server Components or Next.js 15.x and 16.x must immediately patch to the corrected versions to prevent unauthenticated remote code execution, as active exploitation is confirmed.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary