A severe remote code execution vulnerability tracked as CVE-2025-55182 was disclosed in React Server Components and quickly became known as React2Shell, with reporting indicating that exploitation spread soon after public disclosure. Security coverage from eSentire, BitSight, and Computer Weekly described the flaw as affecting React and Next.js environments, warned defenders to assess internet-exposed applications, and noted that attackers were moving from proof-of-concept activity toward broader exploitation.
Public GitHub repositories rapidly appeared with exploit code, scanners, and remediation-focused projects, including tools explicitly labeled for CVE-2025-55182 and React2Shell detection or exploitation. Repositories such as React2Shell-PoC, multiple PoC scanners, auto-exploit projects, and checkers lowered the barrier to weaponization, while at least one repository advertised fixes for React 19 users. The volume and speed of public tooling indicate that organizations running React Server Components or Next.js services faced immediate pressure to identify exposed systems, apply vendor fixes, and monitor for signs of remote code execution attempts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Invicti published a technical write-up describing React2Shell as a critical RCE issue affecting React Server Components and Next.js, covering both CVE-2025-55182 and CVE-2025-66478. The article broadened public understanding of the issue beyond the original single-CVE disclosure before combined PoC tooling appeared publicly.
A GitHub Gist titled "CVE-2025-55182.py" was published, indicating continued public circulation of exploit code for the React2Shell vulnerability. Its appearance shows offensive tooling for CVE-2025-55182 remained available and was still being repackaged after earlier PoC releases.
Another GitHub proof-of-concept repository for CVE-2025-55182 was published, showing continued community replication and circulation of exploit code months after the initial disclosure. This reflects sustained public availability of offensive tooling for the flaw.
A GitHub repository titled React2Shell-PoC was published with exploitation and scanning tools for CVE-2025-55182 and CVE-2025-66478 in Next.js and React Server Components. This expanded public exploit tooling beyond the initial December repositories.
Bitsight released an analysis focused on observed React2Shell exploitations tied to CVE-2025-55182. The report provided additional technical detail and evidence that exploitation activity had become significant enough to study separately.
Computer Weekly reported that security teams were on alert as exploitation of the React2Shell vulnerability spread. This marks an escalation from disclosure and proof-of-concept publication to active exploitation concerns.
Multiple GitHub repositories publishing exploit code, scanners, and workaround material for CVE-2025-55182 were created or made public, including exploit, checker, scanner, and fix-themed projects. Their appearance indicates rapid public weaponization and defender interest immediately after disclosure.
eSentire published a security advisory describing CVE-2025-55182 as a severe remote code execution vulnerability affecting React Server Components. This appears to be the first referenced public disclosure of the flaw later dubbed React2Shell.
17 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegist.github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcecommunity.vercel.com
Open sourcecve.nohackme.com
Open sourceinvicti.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.