CVE-2025-55182

Published Dec 3, 2025

Last updated 6 months ago

Exploit knownCVSS critical 10.0
React
react2shell
npm
Cloud
Business logic
Supply chain
Server
OT

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-55182 is a critical unauthenticated remote code execution (RCE) vulnerability found in React Server Components (RSC) versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. This vulnerability affects packages including `react-server-dom-parcel`, `react-server-dom-turbopack`, and `react-server-dom-webpack`. The flaw stems from insecure deserialization in the RSC payload handling logic, allowing attacker-controlled data to influence server-side execution. Exploitation requires only a crafted HTTP request. Patches are available for React and Next.js. It is recommended to upgrade to patched React versions such as 19.0.1, 19.1.2, or 19.2.1, and to update frameworks like Next.js to their corresponding patched versions.

Description
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Source
cve-assign@fb.com
NVD status
Analyzed
Products
react, next.js

Insights

Analysis from the Intruder Security Team
Published Dec 4, 2025 Updated Dec 9, 2025

This vulnerability allows for code execution via a deserialisation vulnerability within the react-server-dom packages. This will affect React, NextJS and downstream projects who utilise these frameworks.

AssetNote released a technical research post and detection technique which is effective at identifying unpatches instances, where as full RCE chains may fail due to WAF's fingerprinting those payloads and bypasses heavily. Vercel's CEO released a simple breakdown of the issue and how it works.

We have witnessed widespread exploitation activity for this vulnerability, especially exploiting this to deploy an in-memory webshell. There has been some community efforts to detect exploitation activity, however exploiting this vulnerability usually leaves little to no trace which is difficult for defenders.

Patching immediately is the only effective strategy for dealing with this vulnerability.

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Meta React Server Components Remote Code Execution Vulnerability
Exploit added on
Dec 5, 2025
Exploit action due
Dec 26, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-502

Social media

Hype score
Not currently trending
  1. Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2026-5194 3 - CVE-2026-48095 4 - CVE-2026-23652 5 - CVE-2026-45585 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    29 May 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. First machine of @hackthebox_eu 𝗦𝗲𝗮𝘀𝗼𝗻 𝟭𝟭 down. 🔥 Rooted 𝗥𝗲𝗮𝗰𝘁𝗼𝗿 through: CVE-2025-55182 𝗥𝗖𝗘 → SQLite creds → cracked MD5 → Node.js debugger → root Solid box with a real-world vuln chain. Great start to the season

    @sakibulalikhan

    25 May 2026

    210 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  3. React 19 / Next.js 15 のパッチ脆弱性 (CVE-2025-55182 / 55183 / 55184) を手動追跡で素早く対応した話 https://t.co/qnRL6PxeYn #Qiita

    @yousukezan

    25 May 2026

    1122 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2016-5195 3 - CVE-2026-20223 4 - CVE-2026-41940 5 - CVE-2026-41089 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    23 May 2026

    322 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. We identified a large-scale React2Shell (CVE-2025-55182) operation that scanned millions of targets and confirmed 900+ successful exploits. Logs showed an automated pipeline for exploitation, hit scoring, alerting, and secret harvesting. Claude Code and OpenClaw were used as an h

    @TheDFIRReport

    22 May 2026

    5598 Impressions

    20 Retweets

    50 Likes

    32 Bookmarks

    2 Replies

    0 Quotes

  6. use server" isn't a label. It's an exposed endpoint. CVE-2025-55182 proved React Server Components created an implicit RPC layer — no schemas, no explicit contracts. Just vibes and hope. Update your deps. Then actually read what you're exposing. #nextjs #security

    @KumbajiK

    20 May 2026

    304 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2025-55182 demonstrates, once more, the danger of unsafe deserialization and input validation. Our comprehensive write-up for the React2Shell vulnerability is here. 👉 Check it out: https://t.co/t4SMtQadDh #appsec #securecoding #programming https://t.co/zuigwxdFcb

    @secdim

    19 May 2026

    329 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Post this: 🚨 Critical heads-up for Next.js App Router / React Server Components apps: CVE-2025-55182 is a CVSS 10 pre-auth RCE in React Server Components. Upgrade immediately to patched Next.js/React RSC versions and rotate secrets if your app was exposed while unpatched.

    @ryancarson

    15 May 2026

    1085 Impressions

    1 Retweet

    8 Likes

    5 Bookmarks

    12 Replies

    0 Quotes

  9. Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware https://t.co/b4adaWC6ih The article details a sophisticated cyber intrusion involving the EtherRAT malware family, which initially targeted Linux servers via CVE-2025-55182 and later ex… https://t.co/2p26i4AH3

    @f1tym1

    13 May 2026

    216 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 😃ช่องโหว่ความปลอดภัยระดับวิกฤต (2025-2026): พบช่องโหว่ CVE-2025-55182 ที่มีคะแนนความรุนแรงสูงสุด (10/10) ใน React 19 และ Next.js ที

    @natty_z2234

    13 May 2026

    226 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 😃ช่องโหว่ความปลอดภัยระดับวิกฤต (2025-2026): พบช่องโหว่ CVE-2025-55182 ที่มีคะแนนความรุนแรงสูงสุด (10/10) ใน React 19 และ Next.js ที

    @natty_z2234

    13 May 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. EtherRAT → TukTuk C2 → Gentleman Ransomware: confirmed kill chain Initial access: CVE-2025-55182 (React2Shell) Platforms: Linux (Dec 2025) + Windows (Mar 2026) T1190 → T1219 → T1486 DFIR flash alert issued #ThreatIntel #Ransomware #CVE #EtherRAT

    @NoctisIntel

    12 May 2026

    476 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. EtherRAT evolves from Linux-focused attacks (CVE-2025-55182 exploitation) to Windows campaigns, now deploying The Gentleman ransomware via TukTuk C2 infrastructure. Campaign active since December 2025. #DFIR_Radar https://t.co/8zoDtcWpSR

    @DFIR_Radar

    11 May 2026

    376 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  14. Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware https://t.co/HI70ypIvDa The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux

    @f1tym1

    11 May 2026

    214 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2025-55182 React2Shell #bugbounty https://t.co/PMXTwyIivb

    @termireum

    10 May 2026

    2935 Impressions

    0 Retweets

    38 Likes

    21 Bookmarks

    2 Replies

    0 Quotes

  16. BREAKING: Meta discloses critical RCE CVE-2025-55182 "React2Shell" in React Server Components, issues patch and urges millions of affected websites to update immediately. https://t.co/3AtjzzB686

    @threatcluster

    9 May 2026

    277 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. "PCP replaced" - the metric tracked by PCPJack's C2. PCPJack is a Linux credential-stealing worm disclosed May 7, 2026 by SentinelLabs. It exploits five CVEs to spread: - CVE-2025-29927 (Next.js middleware auth bypass) - CVE-2025-55182 "React2Shell" (Next.js Server Actions

    @SecureChap

    8 May 2026

    283 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. CVE-2025-55182 (React2Shell) を含む5つのCVEを悪用 🚨 クラウドインフラ狙う新たなクレデンシャルスティーラー ↓詳細はリプライで #サイバー攻撃 https://t.co/CtBFZnbdRR

    @motch_dev

    8 May 2026

    249 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  19. Released my first blog "Debugging React2Shell (CVE-2025-55182)". In this blog, I have analysed and explained the backend source code of React which caused the React2Shell vulnerability. https://t.co/68ZmsASPfb #cybersecurity #pentesting #react2shell

    @PremLingayat

    6 May 2026

    296 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Recent find by our team using @Huntio🕵️‍♂️ Akia: Exploiting CVE-2025-55182/66478, this French Claude-coded pipeline is a massive secret harvester: 🔹13 Git/8 SMTP APIs 🔹3k+ AWS Keys 🔹250M JS URLs 🔹EVM/BTC/SOL 🔹250+ ENV types 🔹1k+ Cloud paths 🔹300+

    @ctrlaltintel

    6 May 2026

    5207 Impressions

    10 Retweets

    46 Likes

    23 Bookmarks

    0 Replies

    0 Quotes

  21. Love letter ❤️ from a threat actor 🕵️exploiting React2Shell vulnerability (CVE-2025-55182) to spread #Mirai malware ⤵️ fuckoffurlhaus 😂 Payload URLs 🌐: https://t.co/I1E5dZZwDj Mirai botnet C2s 📡: marvisxoxo .st (ISTanCo 🇷🇸) 45.156.87 .231:23789 (AS5

    @packetrat_

    5 May 2026

    264 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. SHADOW-EARTH-053, China-aligned cluster, targets government, defense, and critical infrastructure across Asia and Poland. Initial access via ProxyLogon and CVE-2025-55182 on Exchange and IIS; Godzilla web shells for persistence; ShadowPad and Noodle RAT via DLL sideloading. https

    @MeridianEU

    5 May 2026

    229 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. I just completed React2Shell: CVE-2025-55182 room on TryHackMe! Explore the CVE-2025-55182 vulnerability in React server components. https://t.co/epLt1XRpCD #tryhackme via @tryhackme #Tryhackme #Learning #Consistency

    @LittleSun4lower

    5 May 2026

    157 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Another day, another reminder that vulnerable software is a goldmine for attackers. CVE-2025-55182 exploitation highlights the critical need for rapid patching. If your organization uses Next.js, verify the patch status ASAP! Also, implement strong MFA and rotate credentials for

    @rangeva

    2 May 2026

    145 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials https://t.co/HLfg9Fred8 #CyberSecurity #DataBreach #CredentialTheft #NextJS #Hacking https://t.co/UPEPBbBCOH

    @blueteamsec1

    2 May 2026

    620 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  26. CVE-2025-55182といいCVE-2026-41940といい、なんで俺はCriticalの脆弱性に見舞われるんだ?

    @hrktvl

    1 May 2026

    207 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  27. CVE-2025-55182 (React2Shell) is a CVSS 10.0 unauthenticated RCE affecting React Server Components and frameworks like Next.js. Now on CISA KEV with pu... https://t.co/PZBBcXhRAW

    @yasirrazahaidry

    1 May 2026

    134 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 🛡️ دليل التوعية الأمنية CVE-2025-55182 ⚠️ هذه ليست مجرد ثغرة... هذا درس!" by @nike49424 #DEVCommunity https://t.co/SKtAofFEsL

    @nike49424

    30 Apr 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. React2Shell CVE-2025-55182 の悪用:シークレット窃取と標的の自動選定を AI で実現 https://t.co/hb8TAKVYJN AI ツールと通信アプリを巧みに組み合わせた、きわめて組織的な攻撃キャンペーンを解説する記事です。この大

    @iototsecnews

    30 Apr 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 900+ companies hacked. One vulnerability. One automated pipeline. Hackers are using AI + Telegram bots to exploit React2Shell (CVE-2025-55182) at scale stealing credentials, cloud access, and financial data in minutes. This isn’t random hacking. It’s organized, automated, a

    @MarcelVelica

    28 Apr 2026

    36467 Impressions

    3 Retweets

    143 Likes

    2 Bookmarks

    2 Replies

    0 Quotes

  31. NEW THREAT INTEL: Bissa Scanner -- AI-orchestrated mass exploitation of CVE-2025-55182 (Next.js RCE) and CVE-2025-9501 (W3 Total Cache). 9 detections, 29 IOCs. https://t.co/bVuLbIIj1p #ThreatIntel #CyberSecurity #CVE #Nextjs #WordPress https://t.co/w9wVc3LQZj

    @threadlinqs

    27 Apr 2026

    233 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. Intel Report [CRITICAL] - A newly exposed threat actor infrastructure has revealed a large-scale automated exploitation campaign leveraging a critical vulnerability in Next.js, tracked as CVE-2025-55182 and referred to as "React2Shell," to compromise... https://t.co/DIJWLbVY4k

    @EnigmaGlobalSW

    26 Apr 2026

    175 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. 🚨 React2Shell (CVE-2025-55182) ile Büyük Çaplı Saldırı: 900+ Şirket Tehlikeye Girdi https://t.co/dwbVjtRAwP @LinkedIn aracılığıyla

    @AturcDestek

    25 Apr 2026

    134 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 🚨 Critical Next.js CVE-2025-55182 is being exploited live. Allows app takeover & credential theft. If you deployed via v0/Lovable, verify your version. AI won't auto-patch this. We flag this in VibeShield scans. Update Next.js now! 🔐 #NextJS

    @vibeshield

    24 Apr 2026

    134 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. 🚨 One hacker. One Telegram bot. 900+ companies breached. Bissa Scanner exploited CVE-2025-55182 (React2Shell) at internet scale AWS, OpenAI, Stripe keys all stolen. Full breakdown 👇 https://t.co/sfIX76Be0b #CyberSecurity #ThreatIntel #InfoSec https://t.co/tz1puWxGgd

    @Xploitzone_01

    24 Apr 2026

    139 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. Dr. Tube’s AI-assisted Bissa scanner exploited 900+ companies using React2Shell (CVE-2025-55182) to steal 30,000 .env files. See the AI-led attack workflow. #AICyberAttack #BissaScanner #React2Shell #InfoSec #CyberSecurity #CloudSecurity #DrTube https://t.co/3HmFuBFogI https:/

    @the_yellow_fall

    24 Apr 2026

    434 Impressions

    0 Retweets

    6 Likes

    2 Bookmarks

    0 Replies

    1 Quote

  37. An exposed server reveals AI-driven mass exploitation using Bissa Scanner and React2Shell (CVE-2025-55182), confirming 900+ breaches and harvesting thousands of credentials with Claude Code and Telegram bots. #BissaScanner #AIExploitation https://t.co/2dxCJ3CgRt

    @TweetThreatNews

    23 Apr 2026

    269 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  38. 🔴 CVE-2025-55182 (React2Shell) RCE in React Server Components. no auth. deterministic. Flight checks "has .then?" to detect Promises Object.prototype.then = () => { /* full control */ } write-up: https://t.co/51g0s2jcWJ repo: https://t.co/R6joVAWJTL @reactjs https:/

    @devianntsec

    23 Apr 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. 🔴 CVE-2025-55182 (React2Shell) RCE en React Server Components. sin auth. determinista. probabilidad 1. Flight pregunta "¿tiene .then?" para detectar Promises. Object.prototype.then = () => { /* control total */ } https://t.co/a9k5Hx4fka https://t.co/R6joVAWJTL

    @devianntsec

    23 Apr 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Claude Code + OpenClaw used with the React2Shell (CVE-2025-55182) bug to exploit 900+ targets extracting "tens of thousands of .env files yielding credentials across AI, cloud, payments, messaging, and databases." Threat actor used Telegram for alerting. https://t.co/lFNXznNMzv

    @Jeremy_Kirk

    22 Apr 2026

    387 Impressions

    1 Retweet

    3 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  41. Bissa scanner: open server exposes AI-assisted credential harvesting chaining Claude Code + OpenClaw with React2Shell (CVE-2025-55182). Full operator pipeline caught live. https://t.co/QWVsaNVwQO #infosec #AI #CVE

    @CyberDaily_News

    22 Apr 2026

    185 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. React2Shell(CVE-2025-55182)を悪用し.envファイルを中心に狙った大規模な認証情報窃取(最大のターゲットはAnthropic・Google・OpenAI・Mistral等の生成AIのAPIキー)オペレーションに関する新たなレポートが公開されて

    @MalwareBibleJP

    22 Apr 2026

    985 Impressions

    2 Retweets

    11 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  43. Unit 42 reports a 282% increase in Kubernetes attacks. Stolen tokens and CVE-2025-55182 led to millions in thefts from crypto exchanges. https://t.co/2TiznewFv5 #Security #CloudSecurity #Kubernetes #NorthKorea - Follow for more

    @techzine

    20 Apr 2026

    123 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. Unit 42 ziet Kubernetes-aanvallen met 282% stijgen. Gestolen tokens en CVE-2025-55182 leidden tot miljoenendiefstallen bij cryptobeurzen. https://t.co/FIt7qbDGom #Security #CloudSecurity #Kubernetes #NoordKorea #PaloAltoNetworks

    @Techzinenlbe

    20 Apr 2026

    154 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. A critical remote code execution vulnerability (CVE-2025-55182) affects React Server Components 19.0.0–19.2.0. https://t.co/xRdmnRxePU #CyberSecurity #ReactJS #RCE #CVE202555182 #ReactSecurity #WebSecurity #InfoSec #PatchNow #DevSecOps https://t.co/68BQw1kuvk

    @redsecuretech

    18 Apr 2026

    171 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 【フロカン名古屋は5/9🦘】 フロントエンドカンファレンス名古屋のトークをご紹介! 「CVE-2025-55182の徹底解析と実践的防御設計」 坂津 潤平さん (@saka2jp) https://t.co/IVwzX3VUdK #fec_nagoya

    @fec_nagoya

    18 Apr 2026

    440 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  47. حملة ضخمة تستغل ثـ ـغرة CVE-2025-55182 لاخـ ـتـ راق تطبيقات Next.js وسـ ـرقة بيانات حسـ ـاسة التفاصيل... https://t.co/5hMouXybNi #مركز_الأمن_السيبراني_للابحاث_والدراسات https://t.co/

    @ccforrs

    16 Apr 2026

    74 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. A insight into CVE-2025-55182 that was exploited in a 🇳🇬Bank ● CVSS 10, that's *Critical* risk. ● It has a EPSS of 66.27%, which is the probability of being exploited in the next 30 days. ● CVE-2025-55182 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Explan

    @WaleMicaiah

    16 Apr 2026

    144 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  49. 35 AI-generated CVEs disclosed in March. 6 in January. A 5x jump in 60 days. CVE-2025-55182 alone breached 766 production hosts. If your coding agent runs in someone else's cloud, their sandbox bug is your incident. Managed OpenClaw keeps Claude Code behind your firewall.

    @musiol_martin

    15 Apr 2026

    147 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  50. PoC-CVE-2025-55182 #exploit Proof-of-concept exploit for CVE-2025-55182 (React2Shell) https://t.co/zrUupnstCv https://t.co/oMuXh1odV5

    @Sadishyt

    15 Apr 2026

    166 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations