Critical RCE · CVSS 10.0 · In-the-wild exploitation
React2Shell – critical RCE vulnerability in React Server Components & Next.js
React2Shell (CVE-2025-55182 plus the
Next.js-specific CVE-2025-66478) is a
pre-auth remote code execution vulnerability
in the Flight protocol used by React Server Components. Attackers can use
specially crafted HTTP requests to execute arbitrary code on affected servers -
without prior authentication.
- CVE
CVE-2025-55182
CVE-2025-66478
- Rating
- CVSS 10.0 (critical)
- Attack type
- Pre-auth RCE via unsafe deserialization (Flight protocol)
- Status
- Active scanning & exploitation, patches available
(as of approx. 08 Dec 2025)