React2Shell: maximum severity vulnerability discovered in React
I got an email from Vercel urging to upgrade Next.js based project 3 days ago. POC was published 2 days ago. Today I've checked my logs and I could already see attack attempts.
https://www.tenable.com/blog/react2shell-cve-2025-55182-react-server-components-rceOpen linkView original on lemmy.curiana.net
2 replies
Yeah been scrambling to get this one patched.
We were very lucky that our usage was on the literal version before the affected version. Dodged a bullet.