It’s been about one week since the disclosure of React2Shell (CVE-2025-55182). The initial "drop everything" panic has mostly subsided, and hopefully, your PagerDuty alerts have stopped screaming. Now that the smoke has cleared, we can actually take a breath and look at the wreckage to understand what just happened to the React ecosystem.

For me, the reality of the situation really hit home when I got 8 emails from GCP (Google Cloud). It wasn’t the usual billing alert warning (the other type of email that causes panic). It looked like this:

New Advisory Notification

Dear Google Cloud customer,

You’ve received an important Google Cloud notification affecting your resource...

Notification Title: **Important Security Information Regarding React …

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help