A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Published: 2025-12-04
React2Shell: A critical React flaw allowing unauthenticated RCE. Impacts include Next.js, React Router, and apps using Server Components.
https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/
https://socket.dev/blog/nextjs-moves-to-scheduled-security-releases
https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/
https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.html
https://securelist.com/strikeshark-campaign/120326/
https://securelist.com/container-security-typical-issues/119974/
https://hackread.com/rondodox-botnet-2018-vulnerability-hijack-asus-routers/
https://www.securityweek.com/pcpjack-worm-removes-teampcp-infections-steals-credentials/
https://thehackernews.com/2026/05/pcpjack-credential-stealer-exploits-5.html
https://thehackernews.com/2026/05/china-linked-hackers-target-asian.html
https://thehackernews.com/2026/04/over-1000-exposed-comfyui-instances.html
https://blog.talosintelligence.com/year-in-review-vulnerabilities-old-and-new-and-something-react2/
https://unit42.paloaltonetworks.com/modern-kubernetes-threats/
https://www.securityweek.com/react2shell-exploited-in-large-scale-credential-harvesting-campaign/
https://thehackernews.com/2026/04/hackers-exploit-cve-2025-55182-to.html
https://www.vulncheck.com/blog/return-of-the-kinsing
https://www.bitsight.com/blog/rondodox-botnet-infrastructure-analysis
https://www.infosecurity-magazine.com/news/cloud-attackers-prefer-exploits/
https://www.helpnetsecurity.com/2026/02/25/edge-infrastructure-attacks-internet-wide-exploitation/
https://thehackernews.com/2026/02/wormable-xmrig-campaign-uses-byovd.html
https://www.databreachtoday.com/ai-generated-malware-exploits-react2shell-for-tiny-profit-a-30734
https://thehackernews.com/2026/02/teampcp-worm-exploits-cloud.html
https://thehackernews.com/2026/02/hackers-exploit-react2shell-to-hijack.html
https://www.securityweek.com/cryptominers-reverse-shells-dropped-in-recent-react2shell-attacks/
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://www.sophos.com/en-us/blog/vect-and-teampcp-partner-for-ransomware-campaigns
https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html
https://github.com/iapetus12/hackcar-writeup
https://github.com/r3vpwnx/CVE-2025-55182
https://github.com/Bluex707/React2Shell-CVE-2025-55182-Exploit
https://github.com/ChrisBarack/cve-2025-55182
https://github.com/Mr-Destroyer/CVE-2025-55182
https://github.com/h3n1s3/React2shell-Research
https://github.com/VOE9/cve-explain
https://github.com/kevin9480/Security_incident_report
https://github.com/balochkainat160-cyber/cs50-cybersecurity
https://github.com/dotnetguard/CVE-2025-55182-Exploit
https://github.com/CerberusMrXi/CVE-2025-55182-Advanced-React-Server-Components-RCE-Exploit
https://github.com/0xdak/CVE-2025-71389_exploit
https://github.com/brian-mitchell-sec/http-bait
https://github.com/6t2kydmp8k-jpg/CVE-2025-55182-Vulnerability-Proof-of-Concept-Group-Project-
https://github.com/Jeanback1/exploit-vault
https://github.com/PedroPLCode/CVE-2025-55182_react2shell_exploit.py
https://github.com/se1zer/Nextjs_Exploit_Tool
https://github.com/amnsecurity/reactorwatch-pentest
https://github.com/RootEvil333/CVE-2025-55182
https://github.com/smadonkuan/CVE-LAb
https://github.com/diamorphine666/React2shell-CVE-2025-55182-Exploit
https://github.com/k1llmelira/react2shell-exploit
https://github.com/ev1Ndxrk3e01/public-cve-research
https://github.com/qux-bbb/CVE_exp
https://github.com/Neverland-lcl/Security_OS_CVE
https://github.com/Neverland-lcl/Security_OS
https://github.com/Alejandro609x/JEFAZO-CVE-2025-55182-Checker
https://github.com/AkhmadKholmurodov/React2Shell_Exploit
https://github.com/HaakimSec/zero2shell-50
https://github.com/coldpaper1/react2shell-cve-demo
https://github.com/rvzsec/react2shell
https://github.com/yurahshell/CVE-2025-55182
https://github.com/tanvirahmedcs/CVE-2025-55182
https://github.com/hakkuri01/r2rs
https://github.com/LuizHenz/PoC-CVE-2025-55182
https://github.com/sonnycroco/HTB-Reactor-Linux-Machine---Walkthrough
https://github.com/Jeanback1/react-rsc-cve-2025-55182-lab
https://github.com/lvx9101-ux/CVE-2025-55182
https://github.com/ZeroTrustWraith/Exploit-PoC
https://github.com/Jenderal92/CVE-2025-55182-React2shell
https://github.com/w3nch/CVE-2025-55182-in-go
https://github.com/spabam/exploits
https://github.com/SoWiEee/CVE-Research
https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2025-55182-React2Shell
https://github.com/MuharremK0/Info-Sys-Security-CVE-2025-55182
https://github.com/K3ysTr0K3R/CVE-2025-55182-EXPLOIT
https://github.com/Theori-lO/reactguard
https://github.com/dbwlsdnr95/CVE-Research
https://github.com/shibaaa204/React2Shell
https://github.com/joaoreis13/flight-risk
https://github.com/nextgensoumen/soc-pulse
https://github.com/Mohamedniane/cve-2025-55182-analysis
https://github.com/Esther-tec/cyber-threat-honeypot-system
https://github.com/opsecramdan/react2shell-cve-2025-55182
https://github.com/RewantChaudhari/nextjs-rce-incident-response
https://github.com/kaxm23/rust-cve-2025-55182-scanner
https://github.com/kaxm23/CVE-2025-55182-Auto-Scanner
https://github.com/masterwok/CVE-2025-55182-React2Shell-PoC
https://github.com/porsellaj/cve-2025-55182-react2shell-analysis
https://github.com/aliksir/nextjs-security-scanner
https://github.com/hujiaozhuzhu/CVE-2025-55182_liyon
https://github.com/yashbarot/security-scanner
https://github.com/Noumenon-ai/cve-guard
https://github.com/madetech/cve-scanner
https://github.com/Su1ph3r/vercelsior
https://github.com/l0lsec/cve-2025-55182-lab
https://github.com/devianntsec/CVE-2025-55182
https://github.com/luoluoqingge/CVE-2025-55182
https://github.com/nexxp90/CVE-2025-55182_RCE_Exploit
https://github.com/namoussa2/cve-exploitation-arsenal
https://github.com/namoussa2/scanner-ultimate
https://github.com/EvanThomasLuke/HACK-AGI-CONTAINERS
https://github.com/wnaspy/CVE-POC-WEAPON
https://github.com/luoqichen/CVE-2025-55182-POC
https://github.com/DeDnY/CVE-2025-55182-in-docker
https://github.com/InferiorAK/CVE-2025-55182-React2Shell-Async-Scanner
https://github.com/Agentpathogene/CTf-CVE.py
https://github.com/MrMahile/MassScanning-CVE-2025-55182
https://github.com/revasec/CVE-2025-55182-Interactive-mode
https://github.com/alptexans/RSC-Detect-CVE-2025-55182
https://github.com/Yusril-git/React2Shell-Wazuh-Detection
https://github.com/zaryouhashraf/CVE-2025-55182
https://github.com/0xAshwesker/CVE-2025-55182
https://github.com/yadavnikhil17102004/CVE_Map_hehe
https://github.com/H4R335HR/reactshell
https://github.com/donghass/CVE-Vulnerability-analysis-reports
https://github.com/Wyl-cmd/CVE-2025-55182
https://github.com/BIG02-bot/React2Shell-CVE-2025-55182-An-lise-T-cnica
https://github.com/souza472/exploit-cve-2025
https://github.com/BrianLopezM99/react2shell-CVE-2025-55182
https://github.com/MuhammadUwais/React2Shell
https://github.com/woorifisa-service-dev-6th/tech-seminar-React2Shell
https://github.com/wnaspy/CVE-2025-55182
https://github.com/deepankarkumar1/CVE-2025-55182_Vulnerable-Application
https://github.com/Nullsecur1ty/React2shell-RCE-MassScanner
Published: 2025-12-03
Updated: 2026-08-04
Named Vulnerability: React2ShellKnown Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 10
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99802
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest