A critical vulnerability (CVE-2025-55182) in React's Flight protocol enables remote code execution on servers using React Server Components. The flaw affects Next.js, React Router, Waku, and related frameworks through unsafe deserialization. Proof-of-concept exploits are publicly available and active scanning is underway.
•5m read time• From dynatrace.com
Table of contents
TL;DR:What is React2Shell (CVE-2025-55182)?Technical details of the React2Shell vulnerabilityDetecting React2Shell (CVE-2025-55182) with Runtime Vulnerability AnalyticsTake action nowSort: