CVE-2025-55182 React2Shell: How to detect and fix this vulnerability in React and Next.js?

CVE-2025-55182 React2Shell: A remote code execution vulnerability affecting React and Next.js software

This flaw, referenced as CVE-2025-55182, affects React.js components used in the Next.js framework as well as several other environments, posing a major risk to web applications.

The vulnerability was responsibly disclosed by Lachlan Davidson to the Meta team on November 29, 2025.

On December 3, 2025, the React and Vercel teams published CVE-2025-55182, a critical unauthenticated remote code execution (RCE) flaw affecting React Server Components (RSCs), and released the corresponding patch.

React.js is an open-source JavaScript library developed by Meta, widely used to build dynamic and high-performance user interfaces.

Next.js, meanwhile, is a React-based framework designed by Vercel that provides advanced features such as server-side rendering (SSR) and performance optimization for modern web applications.

This vulnerability is also the subject of alert CERTFR-2025-ALE-014 and is listed in the CISA Known Exploited Vulnerability Catalog.

Which systems are affected by CVE-2025-55182

The vulnerability is present in versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of the following packages:

  • react-server-dom-webpack
  • react-server-dom-parcel
  • react-server-dom-turbopack

These packages are used when your application implements React Server Components or is compatible with this feature.

In addition to these packages, several frameworks and bundlers based on or compatible with React Server are also vulnerable. Here is the list: next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk.

This broad attack surface, combined with the popularity of these tools, increases the risk of widespread exploitation.

Please note that our application does not use these vulnerable components and is therefore not affected by CVE-2025-55182.

Impact and risks associated with the React2Shell vulnerability

Exploiting this vulnerability allows an attacker to execute code on the server side without prior authentication. This capability paves the way for a non-exhaustive list of particularly dangerous scenarios, such as:

  • Sensitive data exfiltration: access to secrets, credentials, and user information.
  • Persistence: deployment of backdoors or web shells to maintain prolonged access.
  • Lateral movement: pivoting to internal systems to expand the compromise.
  • Ransomware deployment: data encryption for extortion purposes.

Additionally, a high number of public proof-of-concept (PoC) exploits are already available.

The attack relies on creating a malicious HTTP request to an endpoint exposing a Server Function, which is then deserialized by React. This allows for remote code execution on the server.

The lack of authentication, the ability to exploit it remotely, and the widespread adoption of React and Next.js create an extreme risk, confirmed by the maximum CVSS score. This type of attack can be automated and used to scan the internet for vulnerable servers, significantly increasing the potential for abuse.

Why are there two CVEs for the same vulnerability?

Although CVE-2025-55182 was assigned to the React2Shell flaw and React technology, a second vulnerability, CVE-2025-66478, was published for the same exposure and is marked as a duplicate on the NVD website. This second identifier concerns Next.js due to a specific detail: React is not included as a standard dependency but is integrated directly ("vendored"). This approach prevents many dependency management tools from automatically detecting the vulnerability. Creating a specific CVE ensures that Next.js users are alerted and can apply the necessary patches.

How can I detect CVE-2025-55182?

Cyberwatch Vulnerability Manager users have been able to detect this vulnerability since December 3, 2025. Please feel free to contact our team for any questions regarding this matter.

cve-2025-55182

Thanks to its network and website scanning tools, Cyberwatch allows you to verify whether your servers are using vulnerable versions of React or Next.js directly via our external scans.

However, identifying the technology and its version can depend on existing configurations and the obfuscation of this information, which is often the case in React production environments.

In a Next.js installation, React is still used, even if it is not always declared as a dependency in the package.json file. For example, with the App Router, Next.js directly integrates a version of React, which can alter traditional detection methods based on its explicit presence.

By analyzing information from the two CVEs linked to React2Shell and cross-referencing it with reliable sources like GitHub, Cyberwatch provides optimized detection and a patch tailored to the technologies detected on your assets.

cve-2025-55182 patch management

Our tool also allows you to perform an authenticated scan on your machines, which audits the server much more precisely and is capable of directly detecting the React packages at the root of the vulnerability so they can be patched more quickly.

Here is an example of commands used by Cyberwatch to extract packages from package-lock.json:

jq -r '

  .packages

  | to_entries[]

  | select(.key | startswith("node_modules/"))

  | "\(.key)\t\(.value.version)"

' package-lock.json

This command lists all installed modules along with their versions, allowing you to check if React or Next.js are present and vulnerable. You can enable the analysis script from the Cyberwatch application configuration interface under the Analysis Policy section by adding the scan titled "Linux application package scan".

Cyberwatch will then suggest the appropriate vulnerability remediation actions.

appropriate vulnerability remediation actions

How can this vulnerability be mitigated?

A fix has been introduced in versions 19.0.1, 19.1.2, and 19.2.1 of the packages listed below:

  • react-server-dom-webpack
  • react-server-dom-parcel
  • react-server-dom-turbopack

The priority is to audit for the presence of these dependencies and update these packages immediately.

For React-based frameworks and bundlers (such as next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk), it is imperative to update the entire framework, as React is integrated directly rather than as a standard dependency. Simply updating the RSC packages is not enough. You can find the list of all update commands on the React website.

Use our product to efficiently identify the presence of CVE-2025-55182 and CVE-2025-66478 vulnerabilities and deploy your remediation actions as quickly as possible. For any questions regarding these detections, contact our team at support@cyberwatch.com or request a demo via the dedicated form.

Thanks for submitting the form.