Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityrapid-weaponizationproof-of-concept-releaseinternet-facing-service-vulnerability

React2Shell RCE in React Server Components Triggers Active Exploitation

Updated 12d agoFirst seen May 25, 202617 sources

A severe remote code execution vulnerability tracked as CVE-2025-55182 was disclosed in React Server Components and quickly became known as React2Shell, with reporting indicating that exploitation spread soon after public disclosure. Security coverage from eSentire, BitSight, and Computer Weekly described the flaw as affecting React and Next.js environments, warned defenders to assess internet-exposed applications, and noted that attackers were moving from proof-of-concept activity toward broader exploitation.

Public GitHub repositories rapidly appeared with exploit code, scanners, and remediation-focused projects, including tools explicitly labeled for CVE-2025-55182 and React2Shell detection or exploitation. Repositories such as React2Shell-PoC, multiple PoC scanners, auto-exploit projects, and checkers lowered the barrier to weaponization, while at least one repository advertised fixes for React 19 users. The volume and speed of public tooling indicate that organizations running React Server Components or Next.js services faced immediate pressure to identify exposed systems, apply vendor fixes, and monitor for signs of remote code execution attempts.

Share:
React2Shell RCE in React Server Components Triggers Active Exploitation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
May 25, 202629d ago

Invicti expands React2Shell coverage to include CVE-2025-66478

Invicti published a technical write-up describing React2Shell as a critical RCE issue affecting React Server Components and Next.js, covering both CVE-2025-55182 and CVE-2025-66478. The article broadened public understanding of the issue beyond the original single-CVE disclosure before combined PoC tooling appeared publicly.

React2Shell: Critical RCE in React Server Components and Next.js (CVE-2025-55182, CVE-2025-66478)
Mar 14, 20263mo ago

GitHub Gist publishes CVE-2025-55182 Python exploit code

A GitHub Gist titled "CVE-2025-55182.py" was published, indicating continued public circulation of exploit code for the React2Shell vulnerability. Its appearance shows offensive tooling for CVE-2025-55182 remained available and was still being repackaged after earlier PoC releases.

CVE-2025-55182.py · GitHub
Feb 4, 20265mo ago

Additional CVE-2025-55182 PoC repository is published

Another GitHub proof-of-concept repository for CVE-2025-55182 was published, showing continued community replication and circulation of exploit code months after the initial disclosure. This reflects sustained public availability of offensive tooling for the flaw.

Jan 5, 20266mo ago

React2Shell combined PoC for CVE-2025-55182 and CVE-2025-66478 is published

A GitHub repository titled React2Shell-PoC was published with exploitation and scanning tools for CVE-2025-55182 and CVE-2025-66478 in Next.js and React Server Components. This expanded public exploit tooling beyond the initial December repositories.

Dec 18, 20256mo ago

Bitsight publishes initial analysis of React2Shell exploitations

Bitsight released an analysis focused on observed React2Shell exploitations tied to CVE-2025-55182. The report provided additional technical detail and evidence that exploitation activity had become significant enough to study separately.

Dec 5, 20257mo ago

Reports warn that React2Shell exploitation is spreading

Computer Weekly reported that security teams were on alert as exploitation of the React2Shell vulnerability spread. This marks an escalation from disclosure and proof-of-concept publication to active exploitation concerns.

Dec 4, 20257mo ago

Public exploit and scanner repositories for CVE-2025-55182 appear on GitHub

Multiple GitHub repositories publishing exploit code, scanners, and workaround material for CVE-2025-55182 were created or made public, including exploit, checker, scanner, and fix-themed projects. Their appearance indicates rapid public weaponization and defender interest immediately after disclosure.

Dec 3, 20257mo ago

eSentire discloses severe React Server Components RCE flaw CVE-2025-55182

eSentire published a security advisory describing CVE-2025-55182 as a severe remote code execution vulnerability affecting React Server Components. This appears to be the first referenced public disclosure of the flaw later dubbed React2Shell.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

React2Shell RCE in React Server Components Triggers Active Exploitation | Mallory