A critical pre-authentication remote code execution flaw, tracked as CVE-2025-55182 and dubbed React2Shell, was disclosed in React Server Components and related React Flight server-side deserialization logic used by React.js, Next.js, and similar frameworks. The vulnerability affects React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 in the packages react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack, where unsafe deserialization of HTTP request payloads sent to Server Function endpoints can lead to arbitrary code execution in Node.js before authentication. Public reporting said the flaw was fixed in the React repository through pull request #35277, and vendor advisories and CISA tracking indicate the issue drew urgent attention.
Security researchers later reported active in-the-wild exploitation beginning almost immediately after disclosure, with mass scanning followed by deployment of Cobalt Strike, Sliver, cryptominers, reverse proxies, a Go backdoor, botnet activity, and a Node.js Secret-Hunter payload aimed at stealing credentials and secrets. Observed campaigns targeted both Linux and Windows systems, and analysis tied the root cause to improper property ownership checks in React's reviveModel function that allowed attacker-controlled serialized payloads to traverse prototype properties. The official patch replaced unsafe ownership checks with Object.prototype.hasOwnProperty.call(...), added explicit handling for __proto__, and prompted guidance to upgrade affected React and Next.js deployments and monitor exposed Server Function endpoints for exploitation attempts.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Trend Micro published an analysis of CVE-2025-55182, detailing the React Flight deserialization flaw, proof-of-concept mechanics, patched code behavior, and in-the-wild exploitation observed after disclosure. The report also documented malware, C2 infrastructure, and credential-theft activity tied to exploitation.
An updated advisory said Next.js was affected by CVE-2025-55182 because it relies on React Server Components, and listed fixed releases 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, and 16.0.7. The advisory also noted that CVE-2025-66478 for Next.js had been marked as a duplicate of CVE-2025-55182.
CISA added CVE-2025-55182 (React2Shell) to its Known Exploited Vulnerabilities catalog, assessing it as actively exploited, automatable, and capable of total technical impact. The KEV metadata identified known ransomware-campaign use and set a December 12 remediation due date.
Jan Schaumann posted CVE-2025-55182 to the oss-security mailing list, describing a critical pre-authentication remote code execution flaw in React Server Components affecting versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. The post said the issue stemmed from unsafe deserialization in Server Function endpoints and referenced a fix in React pull request #35277.
Trend Micro reported a notable surge in exploitation attempts for CVE-2025-55182 between December 5 and December 8, 2025, including mass scanning and multiple emerging campaigns. The activity included Linux and Windows targeting, botnet deployment, and post-exploitation tooling.
A GitNation talk titled "Meet React Flight and Become a RSC Expert" by Mauro Bartolomeoli was published, providing background on React Flight and React Server Components relevant to the later vulnerability story.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourcevulnerability.circl.lu
Open sourcemnemonic.io
Open sourcegitnation.com
Open sourceopenwall.com
Open sourcefacebook.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.