Following reports of active exploitation in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) publicly added a significant security vulnerability affecting React Server Components (RSC) to its Known Exploited Vulnerabilities (KEV) database on Friday.
The vulnerability, CVE-2025-55182 (CVSS score: 10.0), refers to a situation in which an unauthenticated attacker could initiate remote code execution without the need for any special configuration. Additionally, it is monitored as React2Shell.
According to a CISA advisory, Meta React Server Components has a remote code execution vulnerability that could enable unauthenticated remote code execution by taking advantage of a weakness in the way React decodes payloads provided to React Server Function endpoints.
The library’s Flight protocol, which React utilizes to communicate between a server and client read more about Critical React2Shell Flaw Added to CISA KEV After Confirmed Active Exploitation.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
