An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.
https://socket.dev/blog/nextjs-moves-to-scheduled-security-releases
https://cyberscoop.com/react2shell-vulnerability-fallout-spreads/
https://www.theregister.com/2025/12/15/react2shell_flaw_china_iran/
https://www.databreachtoday.com/nation-state-cybercrime-exploits-tied-to-react2shell-a-30285
https://www.theregister.com/2025/12/12/new_react_secretleak_bugs/
https://thehackernews.com/2025/12/new-react-rsc-vulnerabilities-enable.html
https://github.com/lvx9101-ux/CVE-2025-55182
https://github.com/Theori-lO/reactguard
https://github.com/devianntsec/CVE-2025-55182
https://github.com/AndrewMohawk/CVEs
https://github.com/yourpwnguy/cveye
https://github.com/dbwlsdnr95/CVE-2025-55182-React2Shell-Nextjs-RSC-Analysis
https://github.com/pnndrs/react-rsc-cve-scanner
https://github.com/MammaniNelsonD/React2P4IM0Nshell
https://github.com/abdozkaya/rsc-security-auditor
https://github.com/StealthMoud/react-server-cve-lab
https://github.com/asg5704/check-cve
https://github.com/williavs/nextjs-security-update
https://github.com/Saturate/CVE-2025-55183
https://github.com/theori-io/reactguard
https://github.com/hlsitechio/shellockolm
https://github.com/hlsitechio/Shellockolm-AI-CLI-MCP-Scanner
https://github.com/nxgn-kd01/react2shell-scanner