Joy, React2Shell Is a 10/10 RCE Vulnerability Found On Over A Third Of Cloud Environments

Source: Bleeping Computer Joy, React2Shell Is a 10/10 RCE Vulnerability Found On Over A Third Of Cloud Environments

Patch Even If You Haven’t Enabled React Server Components

React2Shell is a new vulnerability which has just been spotted and around 40% of all Cloud environments and 6% of websites are vulnerable to it.  It leverages a flaw in React Server Components and even if your app doesn’t use those components, simply being compatible with them is enough to make you vulnerable.  It’s  a perfect 10 because all it takes is a single HTTP request to trigger it, with a “near-100% reliability” in a successful exploit of the flaw.  In this case exploitation means code execution, the researchers haven’t revealed how large the code payload that React2Shell will be able to trigger as not enough systems have been patched.

This isn’t just small private Cloud environments that are vulnerable, “Meta’s Facebook and Instagram, Netflix, Airbnb, Shopify, Hello Fresh, Walmart, and Asana rely on it” in addition to hoards of developer environments.  You can check your installed version against the list at Bleeping Computer to ensure you get patched, and hope that the large companies are able to patch quickly without breaking things.

The security issue stems from insecure deserialization. It received a severity score of 10/10 and has been assigned the identifiers CVE-2025-55182 for React and CVE-2025-66478 (CVE rejected in the National Vulnerability Database) for Next.js.

Video News

About The Author

Jeremy Hellstrom

Call it K7M.com, AMDMB.com, or PC Perspective, Jeremy has been hanging out and then working with the gang here for years. Apart from the front page you might find him on the BOINC Forums or possibly the Fraggin' Frogs if he has the time.

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Podcasts

Archive & Timeline

Previous 12 months
Explore: All The Years!