Expert View
December 9, 2025
5 min

React2Shell (CVE‑2025‑55182): critical vulnerability in React Server Components

“There is an unauthenticated remote code execution vulnerability in React Server Components. We recommend upgrading immediately.” - Source: React blog post. A critical flaw in React Server Components (RSC) turned into a live-fire event within hours. Public PoCs appeared, cloud providers reported probing at scale, and frameworks rushed patches. If you run React 19 or frameworks that implement RSC (notably Next.js App Router), this is a “upgrade first, investigate next” moment.
Wilfrid BLANC
Co-Founder and Head of Product & Engineering
On this article
Topic part 1

Why is this important?

React2Shell is unauthenticated remote code execution in a mainstream web stack, many internet‑facing apps are reachable by default and public exploits lower the bar for attackers.

A successful hit lets an adversary run code on your servers, harvest secrets (database credentials, API keys, cloud tokens), and pivot into your cloud or data.  CISA added CVE‑2025‑55182 to the Know Exploited Vulnerabilites (KEV) catalog on December 5, 2025, confirming in-the-wild exploitation and setting a remediation deadline.

AWS reports rapid, multi‑actor attempts - including China‑nexus groups - and details hands‑on‑keyboard behavior refining payloads against real targets. - Source: AWS Security blog post.

The right response is fast, targeted reduction: patch the affected services first, rotate sensitive secrets, and validate closure.

What is React2Shell, exactly?

React2Shell (CVE‑2025‑55182) is an unauthenticated RCE caused by unsafe deserialization in RSC's payload decoding for server function endpoints (CWE‑502).

  • Affected upstream packages are react‑server‑dom‑webpack, react‑server‑dom‑parcel, and react‑server‑dom‑turbopack in React 19.0.0, 19.1.0, 19.1.1, and 19.2.0. 🩹 Fixes landed in 19.0.1, 19.1.2, and 19.2.1 - Source: React blog post.
  • Downstream, Next.js App Router is affected across 15.x and 16.x, plus canaries after 14.3.0‑canary.76. 🩹 Patched releases include 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, and 16.0.7, with patched canaries available.

ℹ️ Note: Next.js issued an advisory and dedicated CVE entry (CVE-2025-66478) to track the downstream impact of React2Shell.

Two critical nuances from the React team:

  • Apps may be vulnerable even if you don’t explicitly use server functions ➡️ if they support RSC, they need to be updated.
  • Coordinated mitigations are in place at hosting providers, but you should not rely on them instead of patching.

What is the timeline?

The timeline highlights how quickly this escalated from disclosure to active exploitation:

  • Dec 03: NVD publication and upstream advisory; first public PoCs observed.
  • Dec 03: First weaponized exploit appears (beyond simple PoC).
  • Dec 04: First named threat actor reported engaging the CVE.
  • Dec 05: CISA adds CVE‑2025‑55182 to the KEV catalog (in‑the‑wild exploitation confirmed).
  • Dec 05+: Additional exploit variants surface; continued probing across cloud workloads.

Source: Hackuity - SmartEx² Entreprise module

What to do right now: Patch or Perish!

  • Upgrade React and Next.js to fixed versions per upstream guidance. There is no reliable workaround.
  • Don’t rely on WAF alone. Providers have shipped rules, but they can’t guarantee coverage against evolving variants.
  • If you were online and unpatched after public PoCs, rotate secrets and review logs for suspicious POSTs to server action endpoints, reverse shells, and unexpected process spawns.
  • Patched versions for Next.js:15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, and 16.0.7; patched canaries 15.6.0‑canary.58 and 16.1.0‑canary.12. If on Next.js 14.3.0‑canary.77+ canaries, downgrade to the latest stable 14.x.

Why this matters for CTEM

React2Shell is a landmark vulnerability that demonstrates how quickly a modern software ecosystem can expose thousands of organizations to immediate risk. The combination of:

  • a framework-level flaw,
  • trivial exploitation,
  • widespread usage,
  • and near-instant weaponizationcreates a perfect storm for defenders.

This incident is a powerful reminder that exposure management is no longer optional.

Organizations must be able to dynamically inventory their technologies, measure exposure, prioritize remediation, and react at the pace of attackers.

If you want to see the current SmartEx² Enterprise view for CVE‑2025‑55182 and how to launch a focused remediation campaign in your organization, request a short demo below, and we’ll walk you through it 👇

Wilfrid BLANC
Co-Founder and Head of Product & Engineering
Wilfrid Blanc is Co-Founder and Head of Product & Engineering at Hackuity. A former Ethical Hacker at Lexsi, he brings deep expertise in offensive security and leads Hackuity’s product and engineering roadmap, helping transform how organizations manage and prioritize cyber exposure. When he's not behind his laptop, you'll find him skiing on the slopes of the 3 Vallées in winter or hiking through the mountains in summer.
Ready to see Hackuity in action?
See how Hackuity maps to your tools, teams, and remediation workflows.
Book a demo
Share this post
VR-1
Property
Model type

Post-trained cyber reasoning model

Primary specialization

Multi-domain enterprise attack-chain discovery

Starting condition

A scoped foothold and a concrete objective

Operating surfaces

Cloud, identity, runtime, code, CI/CD, SaaS, and organizational context
xxxxxx

Success signal

Execution-verified completion of the objective

Primary evaluation

IntrusionBench

Preliminary result (preview)

More than 2× black-box pass@3 over the strongest evaluated frontier baseline

Trajectory budget

Two-hour wall-clock limit per trajectory, or 250 agent turns (whichever comes first)

Most recent articals

Hackuity in the News
Article
5 minutes
Hackuity raises $19M Series B to scale the AI-powered Vulnerability Operations Center
Today we announced $19 million in new funding, bringing Hackuity's total funding to $38 million. The round was led by Forgepoint Capital International, alongside our existing investors Bright Pixel, Bpifrance and Seventure Partners.
Patrick RAGARU
Co-founder & CEO
Pierre SAMSON
Co-Founder and Chief Revenue Officer
September 15, 2026
Expert View
Article
5 minutes
All about CTEM in 5 minutes
Security teams do not suffer from a lack of vulnerability data, they suffer from too much of it. What they need is a clear way to prioritize and act on it.
Pierre SAMSON
Co-Founder and Chief Revenue Officer
September 9, 2026
Expert View
8 minutes
MTTR & MTO: The Metrics Everyone Talks About, But Almost No One Calculates Correctly
The KPI Your Clients Always Ask First: No matter the industry, no matter the maturity of the organization: when a CISO or security leader reviews their vulnerability management.
Thomas CHARARA
Product Manager
August 25, 2026

See Hackuity in action

Schedule a personalized demo to see how Hackuity maps to your environment.
Illustration of hackuity presention, Screenshot of the Hackuity Exposure Overview dashboard showing 1 critical, 474 high, and 2.6k other open findings, alongside a 12-month bar chart of findings by severity and a video call panel