React2Shell exploit: What happened and lessons learned
blog.logrocket.com·23h
📘Typescript
Preview
Report Post

On December 3, 2025, a critical vulnerability in React Server Components shocked the web development community. React2Shell(CVE-2025-55182) was disclosed with a CVSS score of 10.0, which is the maximum score for a vulnerability. The bug allowed remote code execution (RCE) on any server running React Server Components (RSC). Within hours of disclosure, Chinese state-sponsored groups and cryptomining operations began exploiting vulnerable servers in the wild.

react 2 shell vulnerability shruti kapoor

This post breaks down what happened, why it happened, and how a subtle design decision in the React Flight protocol turned into one of the…

Similar Posts

Loading similar posts...