CVE-2025-55182

Published Dec 3, 2025

Last updated 8 months ago

Exploit knownCVSS critical 10.0
React
react2shell
npm
AWS
Cloud
Zero-day
ICS
Business logic
Supply chain
Server
OT
Port (443)

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-55182 is a critical unauthenticated remote code execution (RCE) vulnerability found in React Server Components (RSC) versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. This vulnerability affects packages including `react-server-dom-parcel`, `react-server-dom-turbopack`, and `react-server-dom-webpack`. The flaw stems from insecure deserialization in the RSC payload handling logic, allowing attacker-controlled data to influence server-side execution. Exploitation requires only a crafted HTTP request. Patches are available for React and Next.js. It is recommended to upgrade to patched React versions such as 19.0.1, 19.1.2, or 19.2.1, and to update frameworks like Next.js to their corresponding patched versions.

Description
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Source
cve-assign@fb.com
NVD status
Analyzed
Products
react, next.js

Insights

Analysis from the Intruder Security Team
Published Dec 4, 2025 Updated Dec 9, 2025

This vulnerability allows for code execution via a deserialisation vulnerability within the react-server-dom packages. This will affect React, NextJS and downstream projects who utilise these frameworks.

AssetNote released a technical research post and detection technique which is effective at identifying unpatches instances, where as full RCE chains may fail due to WAF's fingerprinting those payloads and bypasses heavily. Vercel's CEO released a simple breakdown of the issue and how it works.

We have witnessed widespread exploitation activity for this vulnerability, especially exploiting this to deploy an in-memory webshell. There has been some community efforts to detect exploitation activity, however exploiting this vulnerability usually leaves little to no trace which is difficult for defenders.

Patching immediately is the only effective strategy for dealing with this vulnerability.

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Meta React Server Components Remote Code Execution Vulnerability
Exploit added on
Dec 5, 2025
Exploit action due
Dec 26, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-502

Social media

Hype score
Not currently trending
  1. Pro pack 1.70 summer release: - React Server RCE CVE-2025-55182 - Tekla Web Viewer Remote File Create Vulnerability - WordPress Madara CVE-2025-4524 - Serva WEB Server Vulnerability - HomeSeer Password Decrypt

    @ExCraft_labs

    26 Jul 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Top KEVs hitting KEVIntel sensors this week: 1. CVE-2021-41773 - 732 2. CVE-2022-47945 - 466 3. CVE-2025-55182 - 337 4. CVE-2026-0770 - 178 5. CVE-2026-63030 - 113 2,497 exploitation attempts from 500 source IPs across our sensors. Patch what attackers are actually exploiting.

    @kev_intel

    23 Jul 2026

    74 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Cytellite recent detection targeting CVE-2025-55182 — Storm Industries LLC Visit -- https://t.co/YQH2PpvPFR #Loginsoft #Cytellite #Cybersecurity #CVE202555182 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/v4pVuVfl74

    @Loginsoft_Intel

    22 Jul 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2025-55182: Critical 10.0 CVSS React Server Components Pre-Auth RCE https://t.co/Ctx79sIUe8 #Cybersecurity #Infosec #AppSec #RCE #React #NextJS #React2Shell #CVE202555182 #PoC #EthicalHacking #BugBounty #PatchNow https://t.co/ouBX3okUGd

    @r0otk3r

    12 Jul 2026

    38 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Hey, world 🤙 I just released a few projects on GitHub: - Two PoCs for #CVE-2022-22965 and #CVE-2025-55182, written in C and Go. - A simple C# project demonstrating how AES encryption works. GitHub: https://t.co/uS2tdeNxeq More CVE exploit are coming, stay tuned Peace, ✌

    @RootEvil333

    8 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-55182: Consolidated Exploitation of React Server Components Is Concerning but Not Catastrophic https://t.co/D5l5KNHi9j #CyberSecurity #DataBreach #Vulnerability

    @cyber_newsroom

    5 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2025-55182 Exploitation Reveals Process Failures in React Server Components Security https://t.co/cXVbudZXGr #CVE2025 #ReactJS #CyberSecurity

    @cyber_newsroom

    5 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2025-55182: React Server Components Under Siege While We Sleep https://t.co/DDNhtCMSbE #CVE2025 #ReactJS #ServerComponents

    @cyber_newsroom

    5 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2025-55182: Consolidated Exploitation of React Server Components Signals Looming Danger https://t.co/2nkEfOrpyx #CVE2025 #CyberSecurity #DataProtection

    @cyber_newsroom

    5 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2025-55182: React Server Components Under Persistent Attack https://t.co/jYHWOC1DzF #CVE2025 #React #CyberSecurity

    @cyber_newsroom

    5 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Vect RaaS and TeamPCP formalize a supply chain-to-ransomware pipeline: credential theft across open-source tooling feeds industrialized extortion across 1,000+ SaaS environments. Key details: - TeamPCP (also known as PCPcat, ShellForce, DeadCatx3) exploited CVE-2025-55182 (CVSS

    @DFIR_Radar

    2 Jul 2026

    212 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  12. CVE-2025-55182 (React2Shell) is a pre-auth RCE in React Server Components. CVSS 10, still exploited in the wild. A malformed RSC payload deserializes straight into code execution. Confirm the version you actually ship is on a patched release, not just whatever latest was.

    @4Ndr3w10000

    30 Jun 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. React ist battle-tested. Und trotzdem reicht ein tiefer Blick für eine ziemlich wilde RCE-Story. Der React2Shell-Artikel von Lachlan Davidson ist starke Security-Lektüre. Aus Protokoll-Neugier plötzlich CVE-2025-55182 wird. https://t.co/p5XVxb1ZgR https://t.co/ZwToWRauCC

    @EngKiosk

    29 Jun 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. TRC analysis shows attackers exploited React2Shell (CVE-2025-55182) within hours of disclosure to deploy cryptominers and establish persistent C2 channels. State-sponsored groups used tunneling tools like MINOCAT across compromised React Server Components. Runtime segmentation

    @aviatrixtrc

    22 Jun 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) - Amazon Web Services #CISO https://t.co/MBIIz5PGiA

    @compuchris

    19 Jun 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. #threatreport #MediumCompleteness Analysis of the APT-C-26 (Lazarus) group's attack operations using CVE-2025-55182 with Copperhedge components | 03-06-2026 Source: https://t.co/EDGdTC2Hmx Key details below ↓ 🧑‍💻Actors/Campaigns: Lazarus (🧠motivation: information_th

    @rst_cloud

    4 Jun 2026

    138 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  17. "APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析" published by Qihoo360. #APT-C-26, #CVE-2025-55182, #Copperhedge, #DPRK, #CTI

    @lazarusholic

    4 Jun 2026

    377 Impressions

    4 Retweets

    8 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  18. 360 Advanced Threat Research Institute states Lazarus used CVE-2025-55182 with Copperhedge Loader and MultiRelay/UAC bypass to breach financial and blockchain targets, enabling persistence, data theft, and C2 communications. https://t.co/0zYiy5JI0u

    @Cyber_O51NT

    4 Jun 2026

    494 Impressions

    1 Retweet

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  19. Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component -- https://t.co/a1D6B4Q49y

    @AndreGironda

    3 Jun 2026

    61 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Analysis of #Lazarus Campaign Exploiting CVE-2025-55182 and Copperhedge Malware This report analyzes an ongoing intrusion campaign launched by the notorious Lazarus Group, leveraging the high-risk unauthenticated remote code execution (RCE) vulnerability CVE-2025-55182 paired htt

    @blackorbird

    3 Jun 2026

    2196 Impressions

    13 Retweets

    31 Likes

    17 Bookmarks

    0 Replies

    0 Quotes

  21. GitHub - Jenderal92/CVE-2025-55182-React2shell: CVE-2025-55182 Exploit Tool – Python 2.7 exploit for Next.js prototype pollution leading to RCE · GitHub https://t.co/t2ytOU3xNn

    @akaclandestine

    1 Jun 2026

    1576 Impressions

    3 Retweets

    11 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  22. Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2026-5194 3 - CVE-2026-48095 4 - CVE-2026-23652 5 - CVE-2026-45585 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    29 May 2026

    97 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  23. First machine of @hackthebox_eu 𝗦𝗲𝗮𝘀𝗼𝗻 𝟭𝟭 down. 🔥 Rooted 𝗥𝗲𝗮𝗰𝘁𝗼𝗿 through: CVE-2025-55182 𝗥𝗖𝗘 → SQLite creds → cracked MD5 → Node.js debugger → root Solid box with a real-world vuln chain. Great start to the season

    @sakibulalikhan

    25 May 2026

    210 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  24. React 19 / Next.js 15 のパッチ脆弱性 (CVE-2025-55182 / 55183 / 55184) を手動追跡で素早く対応した話 https://t.co/qnRL6PxeYn #Qiita

    @yousukezan

    25 May 2026

    1122 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2016-5195 3 - CVE-2026-20223 4 - CVE-2026-41940 5 - CVE-2026-41089 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    23 May 2026

    322 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. We identified a large-scale React2Shell (CVE-2025-55182) operation that scanned millions of targets and confirmed 900+ successful exploits. Logs showed an automated pipeline for exploitation, hit scoring, alerting, and secret harvesting. Claude Code and OpenClaw were used as an h

    @TheDFIRReport

    22 May 2026

    5598 Impressions

    20 Retweets

    50 Likes

    32 Bookmarks

    2 Replies

    0 Quotes

  27. use server" isn't a label. It's an exposed endpoint. CVE-2025-55182 proved React Server Components created an implicit RPC layer — no schemas, no explicit contracts. Just vibes and hope. Update your deps. Then actually read what you're exposing. #nextjs #security

    @KumbajiK

    20 May 2026

    304 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  28. CVE-2025-55182 demonstrates, once more, the danger of unsafe deserialization and input validation. Our comprehensive write-up for the React2Shell vulnerability is here. 👉 Check it out: https://t.co/t4SMtQadDh #appsec #securecoding #programming https://t.co/zuigwxdFcb

    @secdim

    19 May 2026

    329 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Post this: 🚨 Critical heads-up for Next.js App Router / React Server Components apps: CVE-2025-55182 is a CVSS 10 pre-auth RCE in React Server Components. Upgrade immediately to patched Next.js/React RSC versions and rotate secrets if your app was exposed while unpatched.

    @ryancarson

    15 May 2026

    1085 Impressions

    1 Retweet

    8 Likes

    5 Bookmarks

    12 Replies

    0 Quotes

  30. Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware https://t.co/b4adaWC6ih The article details a sophisticated cyber intrusion involving the EtherRAT malware family, which initially targeted Linux servers via CVE-2025-55182 and later ex… https://t.co/2p26i4AH3

    @f1tym1

    13 May 2026

    216 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. 😃ช่องโหว่ความปลอดภัยระดับวิกฤต (2025-2026): พบช่องโหว่ CVE-2025-55182 ที่มีคะแนนความรุนแรงสูงสุด (10/10) ใน React 19 และ Next.js ที

    @natty_z2234

    13 May 2026

    226 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 😃ช่องโหว่ความปลอดภัยระดับวิกฤต (2025-2026): พบช่องโหว่ CVE-2025-55182 ที่มีคะแนนความรุนแรงสูงสุด (10/10) ใน React 19 และ Next.js ที

    @natty_z2234

    13 May 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. EtherRAT → TukTuk C2 → Gentleman Ransomware: confirmed kill chain Initial access: CVE-2025-55182 (React2Shell) Platforms: Linux (Dec 2025) + Windows (Mar 2026) T1190 → T1219 → T1486 DFIR flash alert issued #ThreatIntel #Ransomware #CVE #EtherRAT

    @NoctisIntel

    12 May 2026

    476 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. EtherRAT evolves from Linux-focused attacks (CVE-2025-55182 exploitation) to Windows campaigns, now deploying The Gentleman ransomware via TukTuk C2 infrastructure. Campaign active since December 2025. #DFIR_Radar https://t.co/8zoDtcWpSR

    @DFIR_Radar

    11 May 2026

    376 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  35. Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware https://t.co/HI70ypIvDa The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux

    @f1tym1

    11 May 2026

    214 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. CVE-2025-55182 React2Shell #bugbounty https://t.co/PMXTwyIivb

    @termireum

    10 May 2026

    2935 Impressions

    0 Retweets

    38 Likes

    21 Bookmarks

    2 Replies

    0 Quotes

  37. BREAKING: Meta discloses critical RCE CVE-2025-55182 "React2Shell" in React Server Components, issues patch and urges millions of affected websites to update immediately. https://t.co/3AtjzzB686

    @threatcluster

    9 May 2026

    277 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. "PCP replaced" - the metric tracked by PCPJack's C2. PCPJack is a Linux credential-stealing worm disclosed May 7, 2026 by SentinelLabs. It exploits five CVEs to spread: - CVE-2025-29927 (Next.js middleware auth bypass) - CVE-2025-55182 "React2Shell" (Next.js Server Actions

    @SecureChap

    8 May 2026

    283 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. CVE-2025-55182 (React2Shell) を含む5つのCVEを悪用 🚨 クラウドインフラ狙う新たなクレデンシャルスティーラー ↓詳細はリプライで #サイバー攻撃 https://t.co/CtBFZnbdRR

    @motch_dev

    8 May 2026

    249 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  40. Released my first blog "Debugging React2Shell (CVE-2025-55182)". In this blog, I have analysed and explained the backend source code of React which caused the React2Shell vulnerability. https://t.co/68ZmsASPfb #cybersecurity #pentesting #react2shell

    @PremLingayat

    6 May 2026

    296 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. Recent find by our team using @Huntio🕵️‍♂️ Akia: Exploiting CVE-2025-55182/66478, this French Claude-coded pipeline is a massive secret harvester: 🔹13 Git/8 SMTP APIs 🔹3k+ AWS Keys 🔹250M JS URLs 🔹EVM/BTC/SOL 🔹250+ ENV types 🔹1k+ Cloud paths 🔹300+

    @ctrlaltintel

    6 May 2026

    5207 Impressions

    10 Retweets

    46 Likes

    23 Bookmarks

    0 Replies

    0 Quotes

  42. Love letter ❤️ from a threat actor 🕵️exploiting React2Shell vulnerability (CVE-2025-55182) to spread #Mirai malware ⤵️ fuckoffurlhaus 😂 Payload URLs 🌐: https://t.co/I1E5dZZwDj Mirai botnet C2s 📡: marvisxoxo .st (ISTanCo 🇷🇸) 45.156.87 .231:23789 (AS5

    @packetrat_

    5 May 2026

    264 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. SHADOW-EARTH-053, China-aligned cluster, targets government, defense, and critical infrastructure across Asia and Poland. Initial access via ProxyLogon and CVE-2025-55182 on Exchange and IIS; Godzilla web shells for persistence; ShadowPad and Noodle RAT via DLL sideloading. https

    @MeridianEU

    5 May 2026

    229 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. I just completed React2Shell: CVE-2025-55182 room on TryHackMe! Explore the CVE-2025-55182 vulnerability in React server components. https://t.co/epLt1XRpCD #tryhackme via @tryhackme #Tryhackme #Learning #Consistency

    @LittleSun4lower

    5 May 2026

    157 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. Another day, another reminder that vulnerable software is a goldmine for attackers. CVE-2025-55182 exploitation highlights the critical need for rapid patching. If your organization uses Next.js, verify the patch status ASAP! Also, implement strong MFA and rotate credentials for

    @rangeva

    2 May 2026

    145 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials https://t.co/HLfg9Fred8 #CyberSecurity #DataBreach #CredentialTheft #NextJS #Hacking https://t.co/UPEPBbBCOH

    @blueteamsec1

    2 May 2026

    620 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  47. CVE-2025-55182といいCVE-2026-41940といい、なんで俺はCriticalの脆弱性に見舞われるんだ?

    @hrktvl

    1 May 2026

    207 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  48. CVE-2025-55182 (React2Shell) is a CVSS 10.0 unauthenticated RCE affecting React Server Components and frameworks like Next.js. Now on CISA KEV with pu... https://t.co/PZBBcXhRAW

    @yasirrazahaidry

    1 May 2026

    134 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. 🛡️ دليل التوعية الأمنية CVE-2025-55182 ⚠️ هذه ليست مجرد ثغرة... هذا درس!" by @nike49424 #DEVCommunity https://t.co/SKtAofFEsL

    @nike49424

    30 Apr 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. React2Shell CVE-2025-55182 の悪用:シークレット窃取と標的の自動選定を AI で実現 https://t.co/hb8TAKVYJN AI ツールと通信アプリを巧みに組み合わせた、きわめて組織的な攻撃キャンペーンを解説する記事です。この大

    @iototsecnews

    30 Apr 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations