CVE-2025-55182: Initial Analysis of React2Shell Exploitations
bitsight.com·3d
🚀Indie Hacking
Preview
Report Post

On December 3rd Lachlan Davidson disclosed an unauthenticated remote code execution vulnerability in React Server Components (RSC) that exploits how React.js (and Next.js) decodes payloads sent to React Server Function endpoints. On December 4th we started observing fingerprinting attempts for these vulnerabilities and on December 5th we started observing exploitation attempts. React.js is used by66% of the global digital supply, in the top 0.06% of all technologies.

It took less than 48h for threat actors…

Similar Posts

Loading similar posts...